2019-01-17T11:00:34Z DEBUG Logging to /var/log/ipaupgrade.log 2019-01-17T11:00:34Z DEBUG ipa-server-upgrade was invoked with arguments [] and options: {'skip_version_check': False, 'log_file': None, 'force': False, 'verbose': False, 'quiet': False} 2019-01-17T11:00:34Z DEBUG IPA version 4.6.4-10.el7.centos 2019-01-17T11:00:34Z DEBUG importing all plugin modules in ipaserver.plugins... 2019-01-17T11:00:34Z DEBUG importing plugin module ipaserver.plugins.aci 2019-01-17T11:00:34Z DEBUG importing plugin module ipaserver.plugins.automember 2019-01-17T11:00:34Z DEBUG importing plugin module ipaserver.plugins.automount 2019-01-17T11:00:34Z DEBUG importing plugin module ipaserver.plugins.baseldap 2019-01-17T11:00:34Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2019-01-17T11:00:34Z DEBUG importing plugin module ipaserver.plugins.baseuser 2019-01-17T11:00:34Z DEBUG importing plugin module ipaserver.plugins.batch 2019-01-17T11:00:34Z DEBUG importing plugin module ipaserver.plugins.ca 2019-01-17T11:00:34Z DEBUG importing plugin module ipaserver.plugins.caacl 2019-01-17T11:00:34Z DEBUG importing plugin module ipaserver.plugins.cert 2019-01-17T11:00:34Z DEBUG importing plugin module ipaserver.plugins.certmap 2019-01-17T11:00:34Z DEBUG importing plugin module ipaserver.plugins.certprofile 2019-01-17T11:00:34Z DEBUG importing plugin module ipaserver.plugins.config 2019-01-17T11:00:34Z DEBUG importing plugin module ipaserver.plugins.delegation 2019-01-17T11:00:34Z DEBUG importing plugin module ipaserver.plugins.dns 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.dogtag 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.group 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.hbac 2019-01-17T11:00:35Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.hbactest 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.host 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.idrange 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.idviews 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.internal 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.join 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.ldap2 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.location 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.migration 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.misc 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.netgroup 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.otp 2019-01-17T11:00:35Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.otptoken 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.passwd 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.permission 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.ping 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.pkinit 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.privilege 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.rabase 2019-01-17T11:00:35Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.role 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.schema 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.selfservice 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.server 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.serverrole 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.serverroles 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.service 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.session 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.stageuser 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.sudo 2019-01-17T11:00:35Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.sudorule 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.topology 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.trust 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.user 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.vault 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.virtual 2019-01-17T11:00:35Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.whoami 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2019-01-17T11:00:35Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.install.plugins.dns 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2019-01-17T11:00:35Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2019-01-17T11:00:36Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2019-01-17T11:00:36Z DEBUG Searching for an interface of IP address: ::1 2019-01-17T11:00:36Z DEBUG Testing local IP address: ::1/ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff (interface: lo) 2019-01-17T11:00:36Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:00:36Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:00:36Z INFO Missing version: no platform stored 2019-01-17T11:00:36Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:00:36Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2019-01-17T11:00:36Z DEBUG Starting external process 2019-01-17T11:00:36Z DEBUG args=/bin/systemctl is-active dirsrv@LOCAL.service 2019-01-17T11:00:36Z DEBUG Process finished, return code=3 2019-01-17T11:00:36Z DEBUG stdout=inactive 2019-01-17T11:00:36Z DEBUG stderr= 2019-01-17T11:00:36Z DEBUG Upgrading IPA:. Estimated time: 1 minute 30 seconds 2019-01-17T11:00:36Z DEBUG [1/9]: saving configuration 2019-01-17T11:00:36Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:00:36Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:00:36Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:00:36Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:00:36Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:00:36Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:00:36Z DEBUG duration: 0 seconds 2019-01-17T11:00:36Z DEBUG [2/9]: disabling listeners 2019-01-17T11:00:36Z DEBUG duration: 0 seconds 2019-01-17T11:00:36Z DEBUG [3/9]: enabling DS global lock 2019-01-17T11:00:36Z DEBUG duration: 0 seconds 2019-01-17T11:00:36Z DEBUG [4/9]: disabling Schema Compat 2019-01-17T11:00:36Z DEBUG duration: 0 seconds 2019-01-17T11:00:36Z DEBUG [5/9]: starting directory server 2019-01-17T11:00:36Z DEBUG Starting external process 2019-01-17T11:00:36Z DEBUG args=/bin/systemctl start dirsrv@LOCAL.service 2019-01-17T11:00:40Z DEBUG Process finished, return code=0 2019-01-17T11:00:40Z DEBUG stdout= 2019-01-17T11:00:40Z DEBUG stderr= 2019-01-17T11:00:40Z DEBUG Start of dirsrv@LOCAL.service complete 2019-01-17T11:00:40Z DEBUG Created connection context.ldap2_140490554684880 2019-01-17T11:00:40Z DEBUG duration: 4 seconds 2019-01-17T11:00:40Z DEBUG [6/9]: updating schema 2019-01-17T11:00:40Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-LOCAL.socket conn= 2019-01-17T11:00:41Z DEBUG Processing schema LDIF file /usr/share/ipa/60kerberos.ldif 2019-01-17T11:00:41Z DEBUG Processing schema LDIF file /usr/share/ipa/60samba.ldif 2019-01-17T11:00:41Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.24 NAME 'sambaLMPassword' DESC 'LanManager Password' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 SINGLE-VALUE ) 2019-01-17T11:00:41Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.24 NAME 'sambaLMPassword' DESC 'LanManager Password' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{32} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:00:41Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.20 NAME 'sambaSID' DESC 'Security ID' EQUALITY caseIgnoreIA5Match SUBSTR caseExactIA5SubstringsMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 SINGLE-VALUE ) 2019-01-17T11:00:41Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.20 NAME 'sambaSID' DESC 'Security ID' EQUALITY caseIgnoreIA5Match SUBSTR caseExactIA5SubstringsMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{64} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:00:41Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.38 NAME 'sambaDomainName' DESC 'Windows NT domain to which the user belongs' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 ) 2019-01-17T11:00:41Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.38 NAME 'sambaDomainName' DESC 'Windows NT domain to which the user belongs' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{128} X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:00:41Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.75 NAME 'sambaTrustAuthOutgoing' DESC 'Authentication information for the outgoing portion of a trust' EQUALITY caseExactMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 ) 2019-01-17T11:00:41Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.75 NAME 'sambaTrustAuthOutgoing' DESC 'Authentication information for the outgoing portion of a trust' EQUALITY caseExactMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{1050} X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:00:41Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.74 NAME 'sambaFlatName' DESC 'NetBIOS name of a domain' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 ) 2019-01-17T11:00:41Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.74 NAME 'sambaFlatName' DESC 'NetBIOS name of a domain' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{128} X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:00:41Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.76 NAME 'sambaTrustAuthIncoming' DESC 'Authentication information for the incoming portion of a trust' EQUALITY caseExactMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 ) 2019-01-17T11:00:41Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.76 NAME 'sambaTrustAuthIncoming' DESC 'Authentication information for the incoming portion of a trust' EQUALITY caseExactMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{1050} X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:00:41Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.77 NAME 'sambaSecurityIdentifier' DESC 'SID of a trusted domain' EQUALITY caseIgnoreIA5Match SUBSTR caseExactIA5SubstringsMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 SINGLE-VALUE ) 2019-01-17T11:00:41Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.77 NAME 'sambaSecurityIdentifier' DESC 'SID of a trusted domain' EQUALITY caseIgnoreIA5Match SUBSTR caseExactIA5SubstringsMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{64} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:00:41Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.73 NAME 'sambaTrustPartner' DESC 'Fully qualified name of the domain with which a trust exists' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 ) 2019-01-17T11:00:41Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.73 NAME 'sambaTrustPartner' DESC 'Fully qualified name of the domain with which a trust exists' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{128} X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:00:41Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.33 NAME 'sambaHomeDrive' DESC 'Driver letter of home directory mapping' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 SINGLE-VALUE ) 2019-01-17T11:00:41Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.33 NAME 'sambaHomeDrive' DESC 'Driver letter of home directory mapping' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{4} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:00:41Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.34 NAME 'sambaLogonScript' DESC 'Logon script path' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 SINGLE-VALUE ) 2019-01-17T11:00:41Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.34 NAME 'sambaLogonScript' DESC 'Logon script path' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{255} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:00:41Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.36 NAME 'sambaUserWorkstations' DESC 'List of user workstations the user is allowed to logon to' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 SINGLE-VALUE ) 2019-01-17T11:00:41Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.36 NAME 'sambaUserWorkstations' DESC 'List of user workstations the user is allowed to logon to' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{255} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:00:41Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.37 NAME 'sambaHomePath' DESC 'Home directory UNC path' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 ) 2019-01-17T11:00:41Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.37 NAME 'sambaHomePath' DESC 'Home directory UNC path' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{128} X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:00:41Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.25 NAME 'sambaNTPassword' DESC 'MD4 hash of the unicode password' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 SINGLE-VALUE ) 2019-01-17T11:00:41Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.25 NAME 'sambaNTPassword' DESC 'MD4 hash of the unicode password' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{32} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:00:41Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.23 NAME 'sambaPrimaryGroupSID' DESC 'Primary Group Security ID' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 SINGLE-VALUE ) 2019-01-17T11:00:41Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.23 NAME 'sambaPrimaryGroupSID' DESC 'Primary Group Security ID' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{64} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:00:41Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.55 NAME 'sambaLogonHours' DESC 'Logon Hours' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 SINGLE-VALUE ) 2019-01-17T11:00:41Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.55 NAME 'sambaLogonHours' DESC 'Logon Hours' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{42} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:00:41Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.47 NAME 'sambaMungedDial' DESC 'Base64 encoded user parameter string' EQUALITY caseExactMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 ) 2019-01-17T11:00:41Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.47 NAME 'sambaMungedDial' DESC 'Base64 encoded user parameter string' EQUALITY caseExactMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{1050} X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:00:41Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.78 NAME 'sambaTrustForestTrustInfo' DESC 'Forest trust information for a trusted domain object' EQUALITY caseExactMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 ) 2019-01-17T11:00:41Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.78 NAME 'sambaTrustForestTrustInfo' DESC 'Forest trust information for a trusted domain object' EQUALITY caseExactMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{1050} X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:00:41Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.35 NAME 'sambaProfilePath' DESC 'Roaming profile path' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 SINGLE-VALUE ) 2019-01-17T11:00:41Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.35 NAME 'sambaProfilePath' DESC 'Roaming profile path' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{255} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:00:41Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.54 NAME 'sambaPasswordHistory' DESC 'Concatenated MD5 hashes of the salted NT passwords used on this account' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 ) 2019-01-17T11:00:41Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.54 NAME 'sambaPasswordHistory' DESC 'Concatenated MD5 hashes of the salted NT passwords used on this account' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{32} X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:00:41Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.42 NAME 'sambaOptionName' DESC 'Option Name' EQUALITY caseIgnoreMatch SUBSTR caseIgnoreSubstringsMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 ) 2019-01-17T11:00:41Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.42 NAME 'sambaOptionName' DESC 'Option Name' EQUALITY caseIgnoreMatch SUBSTR caseIgnoreSubstringsMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{256} X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:00:41Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.51 NAME 'sambaSIDList' DESC 'Security ID List' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 ) 2019-01-17T11:00:41Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.51 NAME 'sambaSIDList' DESC 'Security ID List' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{64} X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:00:41Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.26 NAME 'sambaAcctFlags' DESC 'Account Flags' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 SINGLE-VALUE ) 2019-01-17T11:00:41Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.26 NAME 'sambaAcctFlags' DESC 'Account Flags' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{16} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:00:41Z DEBUG Schema modlist: [(0, u'attributetypes', ["( 1.3.6.1.4.1.7165.2.1.24 NAME 'sambaLMPassword' DESC 'LanManager Password' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{32} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.20 NAME 'sambaSID' DESC 'Security ID' EQUALITY caseIgnoreIA5Match SUBSTR caseExactIA5SubstringsMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{64} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.38 NAME 'sambaDomainName' DESC 'Windows NT domain to which the user belongs' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{128} X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.75 NAME 'sambaTrustAuthOutgoing' DESC 'Authentication information for the outgoing portion of a trust' EQUALITY caseExactMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{1050} X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.74 NAME 'sambaFlatName' DESC 'NetBIOS name of a domain' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{128} X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.76 NAME 'sambaTrustAuthIncoming' DESC 'Authentication information for the incoming portion of a trust' EQUALITY caseExactMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{1050} X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.77 NAME 'sambaSecurityIdentifier' DESC 'SID of a trusted domain' EQUALITY caseIgnoreIA5Match SUBSTR caseExactIA5SubstringsMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{64} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.73 NAME 'sambaTrustPartner' DESC 'Fully qualified name of the domain with which a trust exists' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{128} X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.33 NAME 'sambaHomeDrive' DESC 'Driver letter of home directory mapping' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{4} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.34 NAME 'sambaLogonScript' DESC 'Logon script path' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{255} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.36 NAME 'sambaUserWorkstations' DESC 'List of user workstations the user is allowed to logon to' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{255} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.37 NAME 'sambaHomePath' DESC 'Home directory UNC path' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{128} X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.25 NAME 'sambaNTPassword' DESC 'MD4 hash of the unicode password' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{32} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.23 NAME 'sambaPrimaryGroupSID' DESC 'Primary Group Security ID' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{64} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.55 NAME 'sambaLogonHours' DESC 'Logon Hours' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{42} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.47 NAME 'sambaMungedDial' DESC 'Base64 encoded user parameter string' EQUALITY caseExactMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{1050} X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.78 NAME 'sambaTrustForestTrustInfo' DESC 'Forest trust information for a trusted domain object' EQUALITY caseExactMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{1050} X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.35 NAME 'sambaProfilePath' DESC 'Roaming profile path' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{255} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.54 NAME 'sambaPasswordHistory' DESC 'Concatenated MD5 hashes of the salted NT passwords used on this account' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{32} X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.42 NAME 'sambaOptionName' DESC 'Option Name' EQUALITY caseIgnoreMatch SUBSTR caseIgnoreSubstringsMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{256} X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.51 NAME 'sambaSIDList' DESC 'Security ID List' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{64} X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.26 NAME 'sambaAcctFlags' DESC 'Account Flags' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{16} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' )"])] 2019-01-17T11:00:41Z DEBUG Processing schema LDIF file /usr/share/ipa/60ipaconfig.ldif 2019-01-17T11:00:41Z DEBUG Processing schema LDIF file /usr/share/ipa/60basev2.ldif 2019-01-17T11:00:41Z DEBUG Processing schema LDIF file /usr/share/ipa/60basev3.ldif 2019-01-17T11:00:41Z DEBUG Replace: ( 2.16.840.1.113730.3.8.11.51 NAME 'ipaAllowedToPerform' DESC 'DNs allowed to perform an operation' SUP distinguishedName EQUALITY distinguishedNameMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 X-ORIGIN 'IPA v4.0' ) 2019-01-17T11:00:41Z DEBUG with: ( 2.16.840.1.113730.3.8.11.51 NAME 'ipaAllowedToPerform' DESC 'DNs allowed to perform an operation' SUP distinguishedName X-ORIGIN 'IPA v4.0' ) 2019-01-17T11:00:41Z DEBUG Replace: ( 2.16.840.1.113730.3.8.11.14 NAME 'ipaNTTrustPartner' DESC 'Fully qualified name of the domain with which a trust exists' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 ) 2019-01-17T11:00:41Z DEBUG with: ( 2.16.840.1.113730.3.8.11.14 NAME 'ipaNTTrustPartner' DESC 'Fully qualified name of the domain with which a trust exists' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{128} X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:00:41Z DEBUG Replace: ( 2.16.840.1.113730.3.8.11.52 NAME 'ipaProtectedOperation' DESC 'Operation to be protected' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 ) 2019-01-17T11:00:41Z DEBUG with: ( 2.16.840.1.113730.3.8.11.52 NAME 'ipaProtectedOperation' DESC 'Operation to be protected' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{128} X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:00:41Z DEBUG Schema modlist: [(0, u'attributetypes', ["( 2.16.840.1.113730.3.8.11.51 NAME 'ipaAllowedToPerform' DESC 'DNs allowed to perform an operation' SUP distinguishedName X-ORIGIN 'IPA v4.0' )", "( 2.16.840.1.113730.3.8.11.14 NAME 'ipaNTTrustPartner' DESC 'Fully qualified name of the domain with which a trust exists' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{128} X-ORIGIN 'IPA v4.6.4' )", "( 2.16.840.1.113730.3.8.11.52 NAME 'ipaProtectedOperation' DESC 'Operation to be protected' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{128} X-ORIGIN 'IPA v4.6.4' )"])] 2019-01-17T11:00:41Z DEBUG Processing schema LDIF file /usr/share/ipa/60ipapk11.ldif 2019-01-17T11:00:41Z DEBUG Processing schema LDIF file /usr/share/ipa/60ipadns.ldif 2019-01-17T11:00:41Z DEBUG Processing schema LDIF file /usr/share/ipa/60certificate-profiles.ldif 2019-01-17T11:00:41Z DEBUG Replace: ( 2.16.840.1.113730.3.8.21.1.8 NAME 'ipaCaSubjectDN' DESC 'Subject DN' SUP distinguishedName EQUALITY distinguishedNameMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 X-ORIGIN 'IPA v4.4 Lightweight CAs' ) 2019-01-17T11:00:41Z DEBUG with: ( 2.16.840.1.113730.3.8.21.1.8 NAME 'ipaCaSubjectDN' DESC 'Subject DN' SUP distinguishedName X-ORIGIN 'IPA v4.4 Lightweight CAs' ) 2019-01-17T11:00:41Z DEBUG Replace: ( 2.16.840.1.113730.3.8.21.1.7 NAME 'ipaCaIssuerDN' DESC 'Issuer DN' SUP distinguishedName EQUALITY distinguishedNameMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 X-ORIGIN 'IPA v4.4 Lightweight CAs' ) 2019-01-17T11:00:41Z DEBUG with: ( 2.16.840.1.113730.3.8.21.1.7 NAME 'ipaCaIssuerDN' DESC 'Issuer DN' SUP distinguishedName X-ORIGIN 'IPA v4.4 Lightweight CAs' ) 2019-01-17T11:00:41Z DEBUG Schema modlist: [(0, u'attributetypes', ["( 2.16.840.1.113730.3.8.21.1.8 NAME 'ipaCaSubjectDN' DESC 'Subject DN' SUP distinguishedName X-ORIGIN 'IPA v4.4 Lightweight CAs' )", "( 2.16.840.1.113730.3.8.21.1.7 NAME 'ipaCaIssuerDN' DESC 'Issuer DN' SUP distinguishedName X-ORIGIN 'IPA v4.4 Lightweight CAs' )"])] 2019-01-17T11:00:42Z DEBUG Replace: ( 2.16.840.1.113730.3.8.21.2.2 NAME 'ipaCaAcl' SUP ipaAssociation STRUCTURAL MAY ( ipaCaCategory $ ipaCertProfileCategory $ serviceCategory $ ipaMemberCa $ ipaMemberCertProfile $ memberService ) X-ORIGIN 'IPA v4.2' ) 2019-01-17T11:00:42Z DEBUG with: ( 2.16.840.1.113730.3.8.21.2.2 NAME 'ipaCaAcl' SUP ipaAssociation STRUCTURAL MUST cn MAY ( ipaCaCategory $ ipaCertProfileCategory $ userCategory $ hostCategory $ serviceCategory $ ipaMemberCa $ ipaMemberCertProfile $ memberService ) X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:00:42Z DEBUG Schema modlist: [(0, u'objectclasses', ["( 2.16.840.1.113730.3.8.21.2.2 NAME 'ipaCaAcl' SUP ipaAssociation STRUCTURAL MUST cn MAY ( ipaCaCategory $ ipaCertProfileCategory $ userCategory $ hostCategory $ serviceCategory $ ipaMemberCa $ ipaMemberCertProfile $ memberService ) X-ORIGIN 'IPA v4.6.4' )"])] 2019-01-17T11:00:42Z DEBUG Processing schema LDIF file /usr/share/ipa/61kerberos-ipav3.ldif 2019-01-17T11:00:42Z DEBUG Processing schema LDIF file /usr/share/ipa/65ipacertstore.ldif 2019-01-17T11:00:42Z DEBUG Processing schema LDIF file /usr/share/ipa/65ipasudo.ldif 2019-01-17T11:00:42Z DEBUG Processing schema LDIF file /usr/share/ipa/70ipaotp.ldif 2019-01-17T11:00:42Z DEBUG Processing schema LDIF file /usr/share/ipa/70topology.ldif 2019-01-17T11:00:42Z DEBUG Processing schema LDIF file /usr/share/ipa/71idviews.ldif 2019-01-17T11:00:42Z DEBUG Processing schema LDIF file /usr/share/ipa/72domainlevels.ldif 2019-01-17T11:00:42Z DEBUG Processing schema LDIF file /usr/share/ipa/73certmap.ldif 2019-01-17T11:00:42Z DEBUG Processing schema LDIF file /usr/share/ipa/15rfc2307bis.ldif 2019-01-17T11:00:42Z DEBUG Processing schema LDIF file /usr/share/ipa/15rfc4876.ldif 2019-01-17T11:00:42Z DEBUG Processing schema LDIF file /usr/share/ipa/05rfc2247.ldif 2019-01-17T11:00:42Z DEBUG Replace: ( 0.9.2342.19200300.100.1.25 NAME ( 'dc' 'domaincomponent' ) EQUALITY caseIgnoreIA5Match SUBSTR caseIgnoreIA5SubstringsMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 SINGLE-VALUE X-ORIGIN 'RFC 4519' X-DEPRECATED 'domaincomponent' ) 2019-01-17T11:00:42Z DEBUG with: ( 0.9.2342.19200300.100.1.25 NAME ( 'dc' 'domaincomponent' ) DESC 'Standard LDAP attribute type' EQUALITY caseIgnoreIA5Match SUBSTR caseIgnoreIA5SubstringsMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 SINGLE-VALUE X-ORIGIN 'RFC 2247' ) 2019-01-17T11:00:42Z DEBUG Replace: ( 0.9.2342.19200300.100.1.38 NAME 'associatedName' EQUALITY distinguishedNameMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 X-ORIGIN 'RFC 4524' ) 2019-01-17T11:00:42Z DEBUG with: ( 0.9.2342.19200300.100.1.38 NAME 'associatedName' DESC 'Standard LDAP attribute type' SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 X-ORIGIN 'RFC 1274' ) 2019-01-17T11:00:42Z DEBUG Schema modlist: [(0, u'attributetypes', ["( 0.9.2342.19200300.100.1.25 NAME ( 'dc' 'domaincomponent' ) DESC 'Standard LDAP attribute type' EQUALITY caseIgnoreIA5Match SUBSTR caseIgnoreIA5SubstringsMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 SINGLE-VALUE X-ORIGIN 'RFC 2247' )", "( 0.9.2342.19200300.100.1.38 NAME 'associatedName' DESC 'Standard LDAP attribute type' SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 X-ORIGIN 'RFC 1274' )"])] 2019-01-17T11:00:42Z DEBUG Replace: ( 1.3.6.1.4.1.1466.344 NAME 'dcObject' SUP top AUXILIARY MUST dc X-ORIGIN 'RFC 4519' ) 2019-01-17T11:00:42Z DEBUG with: ( 1.3.6.1.4.1.1466.344 NAME 'dcObject' DESC 'Standard LDAP objectclass' SUP top AUXILIARY MUST dc X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:00:42Z DEBUG Replace: ( 0.9.2342.19200300.100.4.13 NAME 'domain' SUP top STRUCTURAL MUST dc MAY ( userPassword $ searchGuide $ seeAlso $ businessCategory $ x121Address $ registeredAddress $ destinationIndicator $ preferredDeliveryMethod $ telexNumber $ teletexTerminalIdentifier $ telephoneNumber $ internationalISDNNumber $ facsimileTelephoneNumber $ street $ postOfficeBox $ postalCode $ postalAddress $ physicalDeliveryOfficeName $ st $ l $ description $ o $ associatedName ) X-ORIGIN 'RFC 4524' ) 2019-01-17T11:00:42Z DEBUG with: ( 0.9.2342.19200300.100.4.13 NAME 'domain' DESC 'Standard LDAP objectclass' SUP top STRUCTURAL MUST dc MAY ( associatedName $ businessCategory $ description $ destinationIndicator $ facsimileTelephoneNumber $ internationalISDNNumber $ l $ o $ physicalDeliveryOfficeName $ postOfficeBox $ postalAddress $ postalCode $ preferredDeliveryMethod $ registeredAddress $ searchGuide $ seeAlso $ st $ street $ telephoneNumber $ teletexTerminalIdentifier $ telexNumber $ userPassword $ x121Address ) X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:00:42Z DEBUG Schema modlist: [(0, u'objectclasses', ["( 1.3.6.1.4.1.1466.344 NAME 'dcObject' DESC 'Standard LDAP objectclass' SUP top AUXILIARY MUST dc X-ORIGIN 'IPA v4.6.4' )", "( 0.9.2342.19200300.100.4.13 NAME 'domain' DESC 'Standard LDAP objectclass' SUP top STRUCTURAL MUST dc MAY ( associatedName $ businessCategory $ description $ destinationIndicator $ facsimileTelephoneNumber $ internationalISDNNumber $ l $ o $ physicalDeliveryOfficeName $ postOfficeBox $ postalAddress $ postalCode $ preferredDeliveryMethod $ registeredAddress $ searchGuide $ seeAlso $ st $ street $ telephoneNumber $ teletexTerminalIdentifier $ telexNumber $ userPassword $ x121Address ) X-ORIGIN 'IPA v4.6.4' )"])] 2019-01-17T11:00:43Z DEBUG Replace: ( 0.9.2342.19200300.100.4.14 NAME 'rFC822localPart' SUP domain STRUCTURAL MAY ( cn $ sn ) X-ORIGIN 'RFC 4524' ) 2019-01-17T11:00:43Z DEBUG with: ( 0.9.2342.19200300.100.4.14 NAME 'RFC822localPart' DESC 'Pilot objectclass' SUP domain STRUCTURAL MAY ( cn $ sn ) X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:00:43Z DEBUG Schema modlist: [(0, u'objectclasses', ["( 0.9.2342.19200300.100.4.14 NAME 'RFC822localPart' DESC 'Pilot objectclass' SUP domain STRUCTURAL MAY ( cn $ sn ) X-ORIGIN 'IPA v4.6.4' )"])] 2019-01-17T11:00:43Z DEBUG duration: 2 seconds 2019-01-17T11:00:43Z DEBUG [7/9]: upgrading server 2019-01-17T11:00:43Z DEBUG importing all plugin modules in ipaserver.plugins... 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.aci 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.automember 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.automount 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.baseldap 2019-01-17T11:00:43Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.baseuser 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.batch 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.ca 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.caacl 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.cert 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.certmap 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.certprofile 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.config 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.delegation 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.dns 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.dogtag 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.group 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.hbac 2019-01-17T11:00:43Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.hbactest 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.host 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.idrange 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.idviews 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.internal 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.join 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.ldap2 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.location 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.migration 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.misc 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.netgroup 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.otp 2019-01-17T11:00:43Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.otptoken 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.passwd 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.permission 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.ping 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.pkinit 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.privilege 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.rabase 2019-01-17T11:00:43Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.role 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.schema 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.selfservice 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.server 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.serverrole 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.serverroles 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.service 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.session 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.stageuser 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.sudo 2019-01-17T11:00:43Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.sudorule 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.topology 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.trust 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.user 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.vault 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.virtual 2019-01-17T11:00:43Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.whoami 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2019-01-17T11:00:43Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.install.plugins.dns 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2019-01-17T11:00:43Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2019-01-17T11:00:44Z DEBUG Created connection context.ldap2_140490524145936 2019-01-17T11:00:44Z DEBUG Destroyed connection context.ldap2_140490524145936 2019-01-17T11:00:44Z DEBUG Created connection context.ldap2_140490524145936 2019-01-17T11:00:44Z DEBUG Parsing update file '/usr/share/ipa/updates/05-pre_upgrade_plugins.update' 2019-01-17T11:00:44Z DEBUG Executing upgrade plugin: update_managed_post_first 2019-01-17T11:00:44Z DEBUG raw: update_managed_post_first 2019-01-17T11:00:44Z DEBUG Executing upgrade plugin: update_replica_attribute_lists 2019-01-17T11:00:44Z DEBUG raw: update_replica_attribute_lists 2019-01-17T11:00:44Z DEBUG Start replication agreement exclude list update task 2019-01-17T11:00:44Z DEBUG Found 0 agreement(s) 2019-01-17T11:00:44Z DEBUG Done updating agreements 2019-01-17T11:00:44Z DEBUG Executing upgrade plugin: update_passync_privilege_check 2019-01-17T11:00:44Z DEBUG raw: update_passync_privilege_check 2019-01-17T11:00:44Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:00:44Z DEBUG Check if there is existing PassSync privilege 2019-01-17T11:00:44Z DEBUG PassSync privilege not found, this is a new update 2019-01-17T11:00:44Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:00:44Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:00:44Z DEBUG Executing upgrade plugin: update_referint 2019-01-17T11:00:44Z DEBUG raw: update_referint 2019-01-17T11:00:44Z DEBUG Upgrading referential integrity plugin configuration 2019-01-17T11:00:44Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-LOCAL.socket from SchemaCache 2019-01-17T11:00:44Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LOCAL.socket conn= 2019-01-17T11:00:44Z DEBUG Initial value: LDAPEntry(ipapython.dn.DN('cn=referential integrity postoperation,cn=plugins,cn=config'), {u'cn': ['referential integrity postoperation'], u'nsslapd-pluginexcludeentryscope': ['cn=provisioning,dc=local'], u'nsslapd-pluginPath': ['libreferint-plugin'], u'nsslapd-plugin-depends-on-type': ['database'], u'nsslapd-pluginVendor': ['389 Project'], u'nsslapd-pluginprecedence': ['40'], u'nsslapd-pluginType': ['betxnpostoperation'], u'referint-logfile': ['/var/log/dirsrv/slapd-LOCAL/referint'], u'nsslapd-pluginInitfunc': ['referint_postop_init'], u'nsslapd-pluginVersion': ['1.3.8.4'], u'referint-update-delay': ['0'], u'nsslapd-plugincontainerscope': ['dc=local'], u'nsslapd-pluginDescription': ['referential integrity plugin'], u'nsslapd-pluginentryscope': ['dc=local'], u'nsslapd-pluginEnabled': ['on'], u'nsslapd-pluginId': ['referint'], u'objectClass': ['top', 'nsSlapdPlugin', 'extensibleObject'], u'referint-membership-attr': ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca', 'ipamembercertprofile', 'ipalocation']}) 2019-01-17T11:00:44Z DEBUG Plugin already uses new style, skipping 2019-01-17T11:00:44Z DEBUG Executing upgrade plugin: update_uniqueness_plugins_to_new_syntax 2019-01-17T11:00:44Z DEBUG raw: update_uniqueness_plugins_to_new_syntax 2019-01-17T11:00:44Z DEBUG No uniqueness plugin entries with old style configuration found 2019-01-17T11:00:44Z DEBUG Parsing update file '/usr/share/ipa/updates/10-config.update' 2019-01-17T11:00:44Z DEBUG Updating existing entry: cn=config 2019-01-17T11:00:44Z DEBUG --------------------------------------------- 2019-01-17T11:00:44Z DEBUG Initial value 2019-01-17T11:00:44Z DEBUG dn: cn=config 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-betype: 2019-01-17T11:00:44Z DEBUG ldbm database 2019-01-17T11:00:44Z DEBUG nsslapd-nagle: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:00:44Z DEBUG 100 2019-01-17T11:00:44Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-referralmode: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:00:44Z DEBUG 5 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:00:44Z DEBUG 64 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:00:44Z DEBUG 500 2019-01-17T11:00:44Z DEBUG passwordMinAlphas: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-readonly: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG passwordLegacyPolicy: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:00:44Z DEBUG allowed 2019-01-17T11:00:44Z DEBUG passwordMinUppers: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-plugin: 2019-01-17T11:00:44Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:00:44Z DEBUG 2097152 2019-01-17T11:00:44Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:00:44Z DEBUG 20971520 2019-01-17T11:00:44Z DEBUG nsslapd-timelimit: 2019-01-17T11:00:44Z DEBUG 3600 2019-01-17T11:00:44Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG passwordMinTokenLength: 2019-01-17T11:00:44Z DEBUG 3 2019-01-17T11:00:44Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:00:44Z DEBUG -10 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:00:44Z DEBUG week 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG passwordMinAge: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:00:44Z DEBUG week 2019-01-17T11:00:44Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:00:44Z DEBUG 60 2019-01-17T11:00:44Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:00:44Z DEBUG 1024 2019-01-17T11:00:44Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG passwordInHistory: 2019-01-17T11:00:44Z DEBUG 6 2019-01-17T11:00:44Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-conntablesize: 2019-01-17T11:00:44Z DEBUG 16384 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:00:44Z DEBUG month 2019-01-17T11:00:44Z DEBUG nsslapd-saslpath: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG passwordMaxAge: 2019-01-17T11:00:44Z DEBUG 8640000 2019-01-17T11:00:44Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:00:44Z DEBUG 5 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:00:44Z DEBUG gidNumber 2019-01-17T11:00:44Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:00:44Z DEBUG day 2019-01-17T11:00:44Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-csnlogging: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-tmpdir: 2019-01-17T11:00:44Z DEBUG /tmp 2019-01-17T11:00:44Z DEBUG passwordResetFailureCount: 2019-01-17T11:00:44Z DEBUG 600 2019-01-17T11:00:44Z DEBUG nsslapd-counters: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-svrtab: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:00:44Z DEBUG month 2019-01-17T11:00:44Z DEBUG nsslapd-minssf: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:00:44Z DEBUG 100 2019-01-17T11:00:44Z DEBUG nsslapd-schemadir: 2019-01-17T11:00:44Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:00:44Z DEBUG nsslapd-localuser: 2019-01-17T11:00:44Z DEBUG dirsrv 2019-01-17T11:00:44Z DEBUG nsslapd-security: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG passwordChange: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-port 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:00:44Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:00:44Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:00:44Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:00:44Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:00:44Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:00:44Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:00:44Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:00:44Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:00:44Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:00:44Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:00:44Z DEBUG passwordMaxFailure: 2019-01-17T11:00:44Z DEBUG 3 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:00:44Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:00:44Z DEBUG 128 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog: 2019-01-17T11:00:44Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:00:44Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-rootdn: 2019-01-17T11:00:44Z DEBUG cn=Directory Manager 2019-01-17T11:00:44Z DEBUG nsslapd-ldifdir: 2019-01-17T11:00:44Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:00:44Z DEBUG 600 2019-01-17T11:00:44Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:00:44Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG passwordMustChange: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG passwordExp: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:00:44Z DEBUG 5 2019-01-17T11:00:44Z DEBUG nsslapd-logging-backend: 2019-01-17T11:00:44Z DEBUG dirsrv-log 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:00:44Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:44Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG aci: 2019-01-17T11:00:44Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:00:44Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:44Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:44Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:44Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:44Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:00:44Z DEBUG 100 2019-01-17T11:00:44Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:00:44Z DEBUG cn=Directory Manager 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG passwordMinLength: 2019-01-17T11:00:44Z DEBUG 8 2019-01-17T11:00:44Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-idletimeout: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:00:44Z DEBUG -10 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:00:44Z DEBUG week 2019-01-17T11:00:44Z DEBUG nsslapd-securePort: 2019-01-17T11:00:44Z DEBUG 636 2019-01-17T11:00:44Z DEBUG nsslapd-snmp-index: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG cn: 2019-01-17T11:00:44Z DEBUG config 2019-01-17T11:00:44Z DEBUG objectClass: 2019-01-17T11:00:44Z DEBUG top 2019-01-17T11:00:44Z DEBUG extensibleObject 2019-01-17T11:00:44Z DEBUG nsslapdConfig 2019-01-17T11:00:44Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG passwordSendExpiringTime: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-hash-filters: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:00:44Z DEBUG next 2019-01-17T11:00:44Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:00:44Z DEBUG -10 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:00:44Z DEBUG 5 2019-01-17T11:00:44Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-listenhost: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:00:44Z DEBUG 600 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog: 2019-01-17T11:00:44Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG passwordCheckSyntax: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG passwordGraceLimit: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG passwordWarning: 2019-01-17T11:00:44Z DEBUG 86400 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:00:44Z DEBUG 600 2019-01-17T11:00:44Z DEBUG nsslapd-instancedir: 2019-01-17T11:00:44Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:00:44Z DEBUG nsslapd-config: 2019-01-17T11:00:44Z DEBUG cn=config 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:00:44Z DEBUG 100 2019-01-17T11:00:44Z DEBUG nsslapd-versionstring: 2019-01-17T11:00:44Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:00:44Z DEBUG 256 2019-01-17T11:00:44Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:00:44Z DEBUG 2097152 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:00:44Z DEBUG month 2019-01-17T11:00:44Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:00:44Z DEBUG SSHA512 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG passwordLockout: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-lockdir: 2019-01-17T11:00:44Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:00:44Z DEBUG nsslapd-certdir: 2019-01-17T11:00:44Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:00:44Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:00:44Z DEBUG 10 2019-01-17T11:00:44Z DEBUG nsslapd-backendconfig: 2019-01-17T11:00:44Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG nsslapd-threadnumber: 2019-01-17T11:00:44Z DEBUG 24 2019-01-17T11:00:44Z DEBUG nsslapd-schemamod: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-localhost: 2019-01-17T11:00:44Z DEBUG centos75.local 2019-01-17T11:00:44Z DEBUG nsslapd-bakdir: 2019-01-17T11:00:44Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:00:44Z DEBUG passwordMin8bit: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:00:44Z DEBUG uidNumber 2019-01-17T11:00:44Z DEBUG nsslapd-validate-cert: 2019-01-17T11:00:44Z DEBUG warn 2019-01-17T11:00:44Z DEBUG passwordMinCategories: 2019-01-17T11:00:44Z DEBUG 3 2019-01-17T11:00:44Z DEBUG passwordMinLowers: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG passwordAdminDN: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG passwordMinSpecials: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:00:44Z DEBUG 100 2019-01-17T11:00:44Z DEBUG nsslapd-lastmod: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:00:44Z DEBUG 40 2019-01-17T11:00:44Z DEBUG passwordMaxRepeats: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:00:44Z DEBUG -1 2019-01-17T11:00:44Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:00:44Z DEBUG none 2019-01-17T11:00:44Z DEBUG nsslapd-result-tweak: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:00:44Z DEBUG month 2019-01-17T11:00:44Z DEBUG passwordUnlock: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-schemacheck: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-maxbersize: 2019-01-17T11:00:44Z DEBUG 209715200 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:00:44Z DEBUG 100 2019-01-17T11:00:44Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:00:44Z DEBUG dc=example,dc=com 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-localssf: 2019-01-17T11:00:44Z DEBUG 71 2019-01-17T11:00:44Z DEBUG nsslapd-sizelimit: 2019-01-17T11:00:44Z DEBUG 2000 2019-01-17T11:00:44Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:00:44Z DEBUG dc=local 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:00:44Z DEBUG 2097152 2019-01-17T11:00:44Z DEBUG passwordLockoutDuration: 2019-01-17T11:00:44Z DEBUG 3600 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-port: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:00:44Z DEBUG 100 2019-01-17T11:00:44Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:00:44Z DEBUG cn=schema 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG cn=monitor 2019-01-17T11:00:44Z DEBUG cn=config 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog: 2019-01-17T11:00:44Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:00:44Z DEBUG 600 2019-01-17T11:00:44Z DEBUG nsslapd-rootpw: 2019-01-17T11:00:44Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:00:44Z DEBUG 300000 2019-01-17T11:00:44Z DEBUG nsslapd-workingdir: 2019-01-17T11:00:44Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-rundir: 2019-01-17T11:00:44Z DEBUG /var/run/dirsrv 2019-01-17T11:00:44Z DEBUG nsslapd-schemareplace: 2019-01-17T11:00:44Z DEBUG replication-only 2019-01-17T11:00:44Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:00:44Z DEBUG 16384 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:00:44Z DEBUG 10000 2019-01-17T11:00:44Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG passwordMinDigits: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:00:44Z DEBUG 5 2019-01-17T11:00:44Z DEBUG passwordStorageScheme: 2019-01-17T11:00:44Z DEBUG SSHA512 2019-01-17T11:00:44Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG only: set nsslapd-ssl-check-hostname to 'on', current value [u'on'] 2019-01-17T11:00:44Z DEBUG only: updated value [u'on'] 2019-01-17T11:00:44Z DEBUG --------------------------------------------- 2019-01-17T11:00:44Z DEBUG Final value after applying updates 2019-01-17T11:00:44Z DEBUG dn: cn=config 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-betype: 2019-01-17T11:00:44Z DEBUG ldbm database 2019-01-17T11:00:44Z DEBUG nsslapd-nagle: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:00:44Z DEBUG 100 2019-01-17T11:00:44Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-referralmode: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:00:44Z DEBUG 5 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:00:44Z DEBUG 64 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:00:44Z DEBUG 500 2019-01-17T11:00:44Z DEBUG passwordMinAlphas: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-readonly: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG passwordLegacyPolicy: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:00:44Z DEBUG allowed 2019-01-17T11:00:44Z DEBUG passwordMinUppers: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-plugin: 2019-01-17T11:00:44Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:00:44Z DEBUG 2097152 2019-01-17T11:00:44Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:00:44Z DEBUG 20971520 2019-01-17T11:00:44Z DEBUG nsslapd-timelimit: 2019-01-17T11:00:44Z DEBUG 3600 2019-01-17T11:00:44Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG passwordMinTokenLength: 2019-01-17T11:00:44Z DEBUG 3 2019-01-17T11:00:44Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:00:44Z DEBUG -10 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:00:44Z DEBUG week 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG passwordMinAge: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:00:44Z DEBUG week 2019-01-17T11:00:44Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:00:44Z DEBUG 60 2019-01-17T11:00:44Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:00:44Z DEBUG 1024 2019-01-17T11:00:44Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG passwordInHistory: 2019-01-17T11:00:44Z DEBUG 6 2019-01-17T11:00:44Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-conntablesize: 2019-01-17T11:00:44Z DEBUG 16384 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:00:44Z DEBUG month 2019-01-17T11:00:44Z DEBUG nsslapd-saslpath: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG passwordMaxAge: 2019-01-17T11:00:44Z DEBUG 8640000 2019-01-17T11:00:44Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:00:44Z DEBUG 5 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:00:44Z DEBUG gidNumber 2019-01-17T11:00:44Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:00:44Z DEBUG day 2019-01-17T11:00:44Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-csnlogging: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-tmpdir: 2019-01-17T11:00:44Z DEBUG /tmp 2019-01-17T11:00:44Z DEBUG passwordResetFailureCount: 2019-01-17T11:00:44Z DEBUG 600 2019-01-17T11:00:44Z DEBUG nsslapd-counters: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-svrtab: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:00:44Z DEBUG month 2019-01-17T11:00:44Z DEBUG nsslapd-minssf: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:00:44Z DEBUG 100 2019-01-17T11:00:44Z DEBUG nsslapd-schemadir: 2019-01-17T11:00:44Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:00:44Z DEBUG nsslapd-localuser: 2019-01-17T11:00:44Z DEBUG dirsrv 2019-01-17T11:00:44Z DEBUG nsslapd-security: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG passwordChange: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-port 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:00:44Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:00:44Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:00:44Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:00:44Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:00:44Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:00:44Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:00:44Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:00:44Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:00:44Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:00:44Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:00:44Z DEBUG passwordMaxFailure: 2019-01-17T11:00:44Z DEBUG 3 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:00:44Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:00:44Z DEBUG 128 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog: 2019-01-17T11:00:44Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:00:44Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-rootdn: 2019-01-17T11:00:44Z DEBUG cn=Directory Manager 2019-01-17T11:00:44Z DEBUG nsslapd-ldifdir: 2019-01-17T11:00:44Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:00:44Z DEBUG 600 2019-01-17T11:00:44Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:00:44Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG passwordMustChange: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG passwordExp: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:00:44Z DEBUG 5 2019-01-17T11:00:44Z DEBUG nsslapd-logging-backend: 2019-01-17T11:00:44Z DEBUG dirsrv-log 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:00:44Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:44Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG aci: 2019-01-17T11:00:44Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:00:44Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:44Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:44Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:44Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:44Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:00:44Z DEBUG 100 2019-01-17T11:00:44Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:00:44Z DEBUG cn=Directory Manager 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG passwordMinLength: 2019-01-17T11:00:44Z DEBUG 8 2019-01-17T11:00:44Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-idletimeout: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:00:44Z DEBUG -10 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:00:44Z DEBUG week 2019-01-17T11:00:44Z DEBUG nsslapd-securePort: 2019-01-17T11:00:44Z DEBUG 636 2019-01-17T11:00:44Z DEBUG nsslapd-snmp-index: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG cn: 2019-01-17T11:00:44Z DEBUG config 2019-01-17T11:00:44Z DEBUG objectClass: 2019-01-17T11:00:44Z DEBUG top 2019-01-17T11:00:44Z DEBUG extensibleObject 2019-01-17T11:00:44Z DEBUG nsslapdConfig 2019-01-17T11:00:44Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG passwordSendExpiringTime: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-hash-filters: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:00:44Z DEBUG next 2019-01-17T11:00:44Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:00:44Z DEBUG -10 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:00:44Z DEBUG 5 2019-01-17T11:00:44Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-listenhost: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:00:44Z DEBUG 600 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog: 2019-01-17T11:00:44Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG passwordCheckSyntax: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG passwordGraceLimit: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG passwordWarning: 2019-01-17T11:00:44Z DEBUG 86400 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:00:44Z DEBUG 600 2019-01-17T11:00:44Z DEBUG nsslapd-instancedir: 2019-01-17T11:00:44Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:00:44Z DEBUG nsslapd-config: 2019-01-17T11:00:44Z DEBUG cn=config 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:00:44Z DEBUG 100 2019-01-17T11:00:44Z DEBUG nsslapd-versionstring: 2019-01-17T11:00:44Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:00:44Z DEBUG 256 2019-01-17T11:00:44Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:00:44Z DEBUG 2097152 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:00:44Z DEBUG month 2019-01-17T11:00:44Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:00:44Z DEBUG SSHA512 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG passwordLockout: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-lockdir: 2019-01-17T11:00:44Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:00:44Z DEBUG nsslapd-certdir: 2019-01-17T11:00:44Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:00:44Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:00:44Z DEBUG 10 2019-01-17T11:00:44Z DEBUG nsslapd-backendconfig: 2019-01-17T11:00:44Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG nsslapd-threadnumber: 2019-01-17T11:00:44Z DEBUG 24 2019-01-17T11:00:44Z DEBUG nsslapd-schemamod: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-localhost: 2019-01-17T11:00:44Z DEBUG centos75.local 2019-01-17T11:00:44Z DEBUG nsslapd-bakdir: 2019-01-17T11:00:44Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:00:44Z DEBUG passwordMin8bit: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:00:44Z DEBUG uidNumber 2019-01-17T11:00:44Z DEBUG nsslapd-validate-cert: 2019-01-17T11:00:44Z DEBUG warn 2019-01-17T11:00:44Z DEBUG passwordMinCategories: 2019-01-17T11:00:44Z DEBUG 3 2019-01-17T11:00:44Z DEBUG passwordMinLowers: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG passwordAdminDN: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG passwordMinSpecials: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:00:44Z DEBUG 100 2019-01-17T11:00:44Z DEBUG nsslapd-lastmod: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:00:44Z DEBUG 40 2019-01-17T11:00:44Z DEBUG passwordMaxRepeats: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:00:44Z DEBUG -1 2019-01-17T11:00:44Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:00:44Z DEBUG none 2019-01-17T11:00:44Z DEBUG nsslapd-result-tweak: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:00:44Z DEBUG month 2019-01-17T11:00:44Z DEBUG passwordUnlock: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-schemacheck: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-maxbersize: 2019-01-17T11:00:44Z DEBUG 209715200 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:00:44Z DEBUG 100 2019-01-17T11:00:44Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:00:44Z DEBUG dc=example,dc=com 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-localssf: 2019-01-17T11:00:44Z DEBUG 71 2019-01-17T11:00:44Z DEBUG nsslapd-sizelimit: 2019-01-17T11:00:44Z DEBUG 2000 2019-01-17T11:00:44Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:00:44Z DEBUG dc=local 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:00:44Z DEBUG 2097152 2019-01-17T11:00:44Z DEBUG passwordLockoutDuration: 2019-01-17T11:00:44Z DEBUG 3600 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-port: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:00:44Z DEBUG 100 2019-01-17T11:00:44Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:00:44Z DEBUG cn=schema 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG cn=monitor 2019-01-17T11:00:44Z DEBUG cn=config 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog: 2019-01-17T11:00:44Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:00:44Z DEBUG 600 2019-01-17T11:00:44Z DEBUG nsslapd-rootpw: 2019-01-17T11:00:44Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:00:44Z DEBUG 300000 2019-01-17T11:00:44Z DEBUG nsslapd-workingdir: 2019-01-17T11:00:44Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-rundir: 2019-01-17T11:00:44Z DEBUG /var/run/dirsrv 2019-01-17T11:00:44Z DEBUG nsslapd-schemareplace: 2019-01-17T11:00:44Z DEBUG replication-only 2019-01-17T11:00:44Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:00:44Z DEBUG 16384 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:00:44Z DEBUG 10000 2019-01-17T11:00:44Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG passwordMinDigits: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:00:44Z DEBUG 5 2019-01-17T11:00:44Z DEBUG passwordStorageScheme: 2019-01-17T11:00:44Z DEBUG SSHA512 2019-01-17T11:00:44Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG [] 2019-01-17T11:00:44Z DEBUG Updated 0 2019-01-17T11:00:44Z DEBUG Done 2019-01-17T11:00:44Z DEBUG Updating existing entry: cn=Kerberos Principal Name,cn=IPA MODRDN,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG --------------------------------------------- 2019-01-17T11:00:44Z DEBUG Initial value 2019-01-17T11:00:44Z DEBUG dn: cn=Kerberos Principal Name,cn=IPA MODRDN,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn: 2019-01-17T11:00:44Z DEBUG Kerberos Principal Name 2019-01-17T11:00:44Z DEBUG objectClass: 2019-01-17T11:00:44Z DEBUG top 2019-01-17T11:00:44Z DEBUG extensibleObject 2019-01-17T11:00:44Z DEBUG ipamodrdntargetattr: 2019-01-17T11:00:44Z DEBUG krbPrincipalName 2019-01-17T11:00:44Z DEBUG ipamodrdnsuffix: 2019-01-17T11:00:44Z DEBUG @LOCAL 2019-01-17T11:00:44Z DEBUG ipamodrdnsourceattr: 2019-01-17T11:00:44Z DEBUG uid 2019-01-17T11:00:44Z DEBUG ipamodrdnfilter: 2019-01-17T11:00:44Z DEBUG (&(objectclass=posixaccount)(objectclass=krbPrincipalAux)) 2019-01-17T11:00:44Z DEBUG ipamodrdnscope: 2019-01-17T11:00:44Z DEBUG dc=local 2019-01-17T11:00:44Z DEBUG remove: '60' from nsslapd-pluginPrecedence, current value [] 2019-01-17T11:00:44Z DEBUG remove: '60' not in nsslapd-pluginPrecedence 2019-01-17T11:00:44Z DEBUG --------------------------------------------- 2019-01-17T11:00:44Z DEBUG Final value after applying updates 2019-01-17T11:00:44Z DEBUG dn: cn=Kerberos Principal Name,cn=IPA MODRDN,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn: 2019-01-17T11:00:44Z DEBUG Kerberos Principal Name 2019-01-17T11:00:44Z DEBUG objectClass: 2019-01-17T11:00:44Z DEBUG top 2019-01-17T11:00:44Z DEBUG extensibleObject 2019-01-17T11:00:44Z DEBUG ipamodrdntargetattr: 2019-01-17T11:00:44Z DEBUG krbPrincipalName 2019-01-17T11:00:44Z DEBUG ipamodrdnsuffix: 2019-01-17T11:00:44Z DEBUG @LOCAL 2019-01-17T11:00:44Z DEBUG ipamodrdnsourceattr: 2019-01-17T11:00:44Z DEBUG uid 2019-01-17T11:00:44Z DEBUG ipamodrdnfilter: 2019-01-17T11:00:44Z DEBUG (&(objectclass=posixaccount)(objectclass=krbPrincipalAux)) 2019-01-17T11:00:44Z DEBUG ipamodrdnscope: 2019-01-17T11:00:44Z DEBUG dc=local 2019-01-17T11:00:44Z DEBUG [] 2019-01-17T11:00:44Z DEBUG Updated 0 2019-01-17T11:00:44Z DEBUG Done 2019-01-17T11:00:44Z DEBUG Updating existing entry: cn=IPA MODRDN,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG --------------------------------------------- 2019-01-17T11:00:44Z DEBUG Initial value 2019-01-17T11:00:44Z DEBUG dn: cn=IPA MODRDN,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:44Z DEBUG IPA MODRDN 2019-01-17T11:00:44Z DEBUG cn: 2019-01-17T11:00:44Z DEBUG IPA MODRDN 2019-01-17T11:00:44Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:44Z DEBUG 1.0 2019-01-17T11:00:44Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:44Z DEBUG IPA MODRDN plugin 2019-01-17T11:00:44Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:44Z DEBUG libipa_modrdn 2019-01-17T11:00:44Z DEBUG objectClass: 2019-01-17T11:00:44Z DEBUG top 2019-01-17T11:00:44Z DEBUG nsSlapdPlugin 2019-01-17T11:00:44Z DEBUG extensibleObject 2019-01-17T11:00:44Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:44Z DEBUG database 2019-01-17T11:00:44Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:44Z DEBUG Red Hat, Inc. 2019-01-17T11:00:44Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:00:44Z DEBUG 60 2019-01-17T11:00:44Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:44Z DEBUG betxnpostoperation 2019-01-17T11:00:44Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:44Z DEBUG ipamodrdn_init 2019-01-17T11:00:44Z DEBUG only: set nsslapd-pluginPrecedence to '60', current value [u'60'] 2019-01-17T11:00:44Z DEBUG only: updated value [u'60'] 2019-01-17T11:00:44Z DEBUG --------------------------------------------- 2019-01-17T11:00:44Z DEBUG Final value after applying updates 2019-01-17T11:00:44Z DEBUG dn: cn=IPA MODRDN,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:44Z DEBUG IPA MODRDN 2019-01-17T11:00:44Z DEBUG cn: 2019-01-17T11:00:44Z DEBUG IPA MODRDN 2019-01-17T11:00:44Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:44Z DEBUG 1.0 2019-01-17T11:00:44Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:44Z DEBUG IPA MODRDN plugin 2019-01-17T11:00:44Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:44Z DEBUG libipa_modrdn 2019-01-17T11:00:44Z DEBUG objectClass: 2019-01-17T11:00:44Z DEBUG top 2019-01-17T11:00:44Z DEBUG nsSlapdPlugin 2019-01-17T11:00:44Z DEBUG extensibleObject 2019-01-17T11:00:44Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:44Z DEBUG database 2019-01-17T11:00:44Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:44Z DEBUG Red Hat, Inc. 2019-01-17T11:00:44Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:00:44Z DEBUG 60 2019-01-17T11:00:44Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:44Z DEBUG betxnpostoperation 2019-01-17T11:00:44Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:44Z DEBUG ipamodrdn_init 2019-01-17T11:00:44Z DEBUG [] 2019-01-17T11:00:44Z DEBUG Updated 0 2019-01-17T11:00:44Z DEBUG Done 2019-01-17T11:00:44Z DEBUG Updating existing entry: cn=config 2019-01-17T11:00:44Z DEBUG --------------------------------------------- 2019-01-17T11:00:44Z DEBUG Initial value 2019-01-17T11:00:44Z DEBUG dn: cn=config 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-betype: 2019-01-17T11:00:44Z DEBUG ldbm database 2019-01-17T11:00:44Z DEBUG nsslapd-nagle: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:00:44Z DEBUG 100 2019-01-17T11:00:44Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-referralmode: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:00:44Z DEBUG 5 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:00:44Z DEBUG 64 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:00:44Z DEBUG 500 2019-01-17T11:00:44Z DEBUG passwordMinAlphas: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-readonly: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG passwordLegacyPolicy: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:00:44Z DEBUG allowed 2019-01-17T11:00:44Z DEBUG passwordMinUppers: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-plugin: 2019-01-17T11:00:44Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:00:44Z DEBUG 2097152 2019-01-17T11:00:44Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:00:44Z DEBUG 20971520 2019-01-17T11:00:44Z DEBUG nsslapd-timelimit: 2019-01-17T11:00:44Z DEBUG 3600 2019-01-17T11:00:44Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG passwordMinTokenLength: 2019-01-17T11:00:44Z DEBUG 3 2019-01-17T11:00:44Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:00:44Z DEBUG -10 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:00:44Z DEBUG week 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG passwordMinAge: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:00:44Z DEBUG week 2019-01-17T11:00:44Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:00:44Z DEBUG 60 2019-01-17T11:00:44Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:00:44Z DEBUG 1024 2019-01-17T11:00:44Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG passwordInHistory: 2019-01-17T11:00:44Z DEBUG 6 2019-01-17T11:00:44Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-conntablesize: 2019-01-17T11:00:44Z DEBUG 16384 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:00:44Z DEBUG month 2019-01-17T11:00:44Z DEBUG nsslapd-saslpath: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG passwordMaxAge: 2019-01-17T11:00:44Z DEBUG 8640000 2019-01-17T11:00:44Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:00:44Z DEBUG 5 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:00:44Z DEBUG gidNumber 2019-01-17T11:00:44Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:00:44Z DEBUG day 2019-01-17T11:00:44Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-csnlogging: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-tmpdir: 2019-01-17T11:00:44Z DEBUG /tmp 2019-01-17T11:00:44Z DEBUG passwordResetFailureCount: 2019-01-17T11:00:44Z DEBUG 600 2019-01-17T11:00:44Z DEBUG nsslapd-counters: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-svrtab: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:00:44Z DEBUG month 2019-01-17T11:00:44Z DEBUG nsslapd-minssf: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:00:44Z DEBUG 100 2019-01-17T11:00:44Z DEBUG nsslapd-schemadir: 2019-01-17T11:00:44Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:00:44Z DEBUG nsslapd-localuser: 2019-01-17T11:00:44Z DEBUG dirsrv 2019-01-17T11:00:44Z DEBUG nsslapd-security: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG passwordChange: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-port 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:00:44Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:00:44Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:00:44Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:00:44Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:00:44Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:00:44Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:00:44Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:00:44Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:00:44Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:00:44Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:00:44Z DEBUG passwordMaxFailure: 2019-01-17T11:00:44Z DEBUG 3 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:00:44Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:00:44Z DEBUG 128 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog: 2019-01-17T11:00:44Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:00:44Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-rootdn: 2019-01-17T11:00:44Z DEBUG cn=Directory Manager 2019-01-17T11:00:44Z DEBUG nsslapd-ldifdir: 2019-01-17T11:00:44Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:00:44Z DEBUG 600 2019-01-17T11:00:44Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:00:44Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG passwordMustChange: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG passwordExp: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:00:44Z DEBUG 5 2019-01-17T11:00:44Z DEBUG nsslapd-logging-backend: 2019-01-17T11:00:44Z DEBUG dirsrv-log 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:00:44Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:44Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG aci: 2019-01-17T11:00:44Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:00:44Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:44Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:44Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:44Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:44Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:00:44Z DEBUG 100 2019-01-17T11:00:44Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:00:44Z DEBUG cn=Directory Manager 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG passwordMinLength: 2019-01-17T11:00:44Z DEBUG 8 2019-01-17T11:00:44Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-idletimeout: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:00:44Z DEBUG -10 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:00:44Z DEBUG week 2019-01-17T11:00:44Z DEBUG nsslapd-securePort: 2019-01-17T11:00:44Z DEBUG 636 2019-01-17T11:00:44Z DEBUG nsslapd-snmp-index: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG cn: 2019-01-17T11:00:44Z DEBUG config 2019-01-17T11:00:44Z DEBUG objectClass: 2019-01-17T11:00:44Z DEBUG top 2019-01-17T11:00:44Z DEBUG extensibleObject 2019-01-17T11:00:44Z DEBUG nsslapdConfig 2019-01-17T11:00:44Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG passwordSendExpiringTime: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-hash-filters: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:00:44Z DEBUG next 2019-01-17T11:00:44Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:00:44Z DEBUG -10 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:00:44Z DEBUG 5 2019-01-17T11:00:44Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-listenhost: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:00:44Z DEBUG 600 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog: 2019-01-17T11:00:44Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG passwordCheckSyntax: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG passwordGraceLimit: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG passwordWarning: 2019-01-17T11:00:44Z DEBUG 86400 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:00:44Z DEBUG 600 2019-01-17T11:00:44Z DEBUG nsslapd-instancedir: 2019-01-17T11:00:44Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:00:44Z DEBUG nsslapd-config: 2019-01-17T11:00:44Z DEBUG cn=config 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:00:44Z DEBUG 100 2019-01-17T11:00:44Z DEBUG nsslapd-versionstring: 2019-01-17T11:00:44Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:00:44Z DEBUG 256 2019-01-17T11:00:44Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:00:44Z DEBUG 2097152 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:00:44Z DEBUG month 2019-01-17T11:00:44Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:00:44Z DEBUG SSHA512 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG passwordLockout: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-lockdir: 2019-01-17T11:00:44Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:00:44Z DEBUG nsslapd-certdir: 2019-01-17T11:00:44Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:00:44Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:00:44Z DEBUG 10 2019-01-17T11:00:44Z DEBUG nsslapd-backendconfig: 2019-01-17T11:00:44Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG nsslapd-threadnumber: 2019-01-17T11:00:44Z DEBUG 24 2019-01-17T11:00:44Z DEBUG nsslapd-schemamod: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-localhost: 2019-01-17T11:00:44Z DEBUG centos75.local 2019-01-17T11:00:44Z DEBUG nsslapd-bakdir: 2019-01-17T11:00:44Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:00:44Z DEBUG passwordMin8bit: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:00:44Z DEBUG uidNumber 2019-01-17T11:00:44Z DEBUG nsslapd-validate-cert: 2019-01-17T11:00:44Z DEBUG warn 2019-01-17T11:00:44Z DEBUG passwordMinCategories: 2019-01-17T11:00:44Z DEBUG 3 2019-01-17T11:00:44Z DEBUG passwordMinLowers: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG passwordAdminDN: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG passwordMinSpecials: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:00:44Z DEBUG 100 2019-01-17T11:00:44Z DEBUG nsslapd-lastmod: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:00:44Z DEBUG 40 2019-01-17T11:00:44Z DEBUG passwordMaxRepeats: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:00:44Z DEBUG -1 2019-01-17T11:00:44Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:00:44Z DEBUG none 2019-01-17T11:00:44Z DEBUG nsslapd-result-tweak: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:00:44Z DEBUG month 2019-01-17T11:00:44Z DEBUG passwordUnlock: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-schemacheck: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-maxbersize: 2019-01-17T11:00:44Z DEBUG 209715200 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:00:44Z DEBUG 100 2019-01-17T11:00:44Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:00:44Z DEBUG dc=example,dc=com 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-localssf: 2019-01-17T11:00:44Z DEBUG 71 2019-01-17T11:00:44Z DEBUG nsslapd-sizelimit: 2019-01-17T11:00:44Z DEBUG 2000 2019-01-17T11:00:44Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:00:44Z DEBUG dc=local 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:00:44Z DEBUG 2097152 2019-01-17T11:00:44Z DEBUG passwordLockoutDuration: 2019-01-17T11:00:44Z DEBUG 3600 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-port: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:00:44Z DEBUG 100 2019-01-17T11:00:44Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:00:44Z DEBUG cn=schema 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG cn=monitor 2019-01-17T11:00:44Z DEBUG cn=config 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog: 2019-01-17T11:00:44Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:00:44Z DEBUG 600 2019-01-17T11:00:44Z DEBUG nsslapd-rootpw: 2019-01-17T11:00:44Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:00:44Z DEBUG 300000 2019-01-17T11:00:44Z DEBUG nsslapd-workingdir: 2019-01-17T11:00:44Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-rundir: 2019-01-17T11:00:44Z DEBUG /var/run/dirsrv 2019-01-17T11:00:44Z DEBUG nsslapd-schemareplace: 2019-01-17T11:00:44Z DEBUG replication-only 2019-01-17T11:00:44Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:00:44Z DEBUG 16384 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:00:44Z DEBUG 10000 2019-01-17T11:00:44Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG passwordMinDigits: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:00:44Z DEBUG 5 2019-01-17T11:00:44Z DEBUG passwordStorageScheme: 2019-01-17T11:00:44Z DEBUG SSHA512 2019-01-17T11:00:44Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG --------------------------------------------- 2019-01-17T11:00:44Z DEBUG Final value after applying updates 2019-01-17T11:00:44Z DEBUG dn: cn=config 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-betype: 2019-01-17T11:00:44Z DEBUG ldbm database 2019-01-17T11:00:44Z DEBUG nsslapd-nagle: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:00:44Z DEBUG 100 2019-01-17T11:00:44Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-referralmode: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:00:44Z DEBUG 5 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:00:44Z DEBUG 64 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:00:44Z DEBUG 500 2019-01-17T11:00:44Z DEBUG passwordMinAlphas: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-readonly: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG passwordLegacyPolicy: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:00:44Z DEBUG allowed 2019-01-17T11:00:44Z DEBUG passwordMinUppers: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-plugin: 2019-01-17T11:00:44Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:00:44Z DEBUG 2097152 2019-01-17T11:00:44Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:00:44Z DEBUG 20971520 2019-01-17T11:00:44Z DEBUG nsslapd-timelimit: 2019-01-17T11:00:44Z DEBUG 3600 2019-01-17T11:00:44Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG passwordMinTokenLength: 2019-01-17T11:00:44Z DEBUG 3 2019-01-17T11:00:44Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:00:44Z DEBUG -10 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:00:44Z DEBUG week 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG passwordMinAge: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:00:44Z DEBUG week 2019-01-17T11:00:44Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:00:44Z DEBUG 60 2019-01-17T11:00:44Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:00:44Z DEBUG 1024 2019-01-17T11:00:44Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG passwordInHistory: 2019-01-17T11:00:44Z DEBUG 6 2019-01-17T11:00:44Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-conntablesize: 2019-01-17T11:00:44Z DEBUG 16384 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:00:44Z DEBUG month 2019-01-17T11:00:44Z DEBUG nsslapd-saslpath: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG passwordMaxAge: 2019-01-17T11:00:44Z DEBUG 8640000 2019-01-17T11:00:44Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:00:44Z DEBUG 5 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:00:44Z DEBUG gidNumber 2019-01-17T11:00:44Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:00:44Z DEBUG day 2019-01-17T11:00:44Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-csnlogging: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-tmpdir: 2019-01-17T11:00:44Z DEBUG /tmp 2019-01-17T11:00:44Z DEBUG passwordResetFailureCount: 2019-01-17T11:00:44Z DEBUG 600 2019-01-17T11:00:44Z DEBUG nsslapd-counters: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-svrtab: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:00:44Z DEBUG month 2019-01-17T11:00:44Z DEBUG nsslapd-minssf: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:00:44Z DEBUG 100 2019-01-17T11:00:44Z DEBUG nsslapd-schemadir: 2019-01-17T11:00:44Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:00:44Z DEBUG nsslapd-localuser: 2019-01-17T11:00:44Z DEBUG dirsrv 2019-01-17T11:00:44Z DEBUG nsslapd-security: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG passwordChange: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-port 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:00:44Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:00:44Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:00:44Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:00:44Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:00:44Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:00:44Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:00:44Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:00:44Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:00:44Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:00:44Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:00:44Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:00:44Z DEBUG passwordMaxFailure: 2019-01-17T11:00:44Z DEBUG 3 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:00:44Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:00:44Z DEBUG 128 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog: 2019-01-17T11:00:44Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:00:44Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-rootdn: 2019-01-17T11:00:44Z DEBUG cn=Directory Manager 2019-01-17T11:00:44Z DEBUG nsslapd-ldifdir: 2019-01-17T11:00:44Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:00:44Z DEBUG 600 2019-01-17T11:00:44Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:00:44Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG passwordMustChange: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG passwordExp: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:00:44Z DEBUG 5 2019-01-17T11:00:44Z DEBUG nsslapd-logging-backend: 2019-01-17T11:00:44Z DEBUG dirsrv-log 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:00:44Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:44Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG aci: 2019-01-17T11:00:44Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:00:44Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:44Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:44Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:44Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:44Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:00:44Z DEBUG 100 2019-01-17T11:00:44Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:00:44Z DEBUG cn=Directory Manager 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG passwordMinLength: 2019-01-17T11:00:44Z DEBUG 8 2019-01-17T11:00:44Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-idletimeout: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:00:44Z DEBUG -10 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:00:44Z DEBUG week 2019-01-17T11:00:44Z DEBUG nsslapd-securePort: 2019-01-17T11:00:44Z DEBUG 636 2019-01-17T11:00:44Z DEBUG nsslapd-snmp-index: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG cn: 2019-01-17T11:00:44Z DEBUG config 2019-01-17T11:00:44Z DEBUG objectClass: 2019-01-17T11:00:44Z DEBUG top 2019-01-17T11:00:44Z DEBUG extensibleObject 2019-01-17T11:00:44Z DEBUG nsslapdConfig 2019-01-17T11:00:44Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG passwordSendExpiringTime: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-hash-filters: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:00:44Z DEBUG next 2019-01-17T11:00:44Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:00:44Z DEBUG -10 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:00:44Z DEBUG 5 2019-01-17T11:00:44Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-listenhost: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:00:44Z DEBUG 600 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog: 2019-01-17T11:00:44Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG passwordCheckSyntax: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG passwordGraceLimit: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG passwordWarning: 2019-01-17T11:00:44Z DEBUG 86400 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:00:44Z DEBUG 600 2019-01-17T11:00:44Z DEBUG nsslapd-instancedir: 2019-01-17T11:00:44Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:00:44Z DEBUG nsslapd-config: 2019-01-17T11:00:44Z DEBUG cn=config 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:00:44Z DEBUG 100 2019-01-17T11:00:44Z DEBUG nsslapd-versionstring: 2019-01-17T11:00:44Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:00:44Z DEBUG 256 2019-01-17T11:00:44Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:00:44Z DEBUG 2097152 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:00:44Z DEBUG month 2019-01-17T11:00:44Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:00:44Z DEBUG SSHA512 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG passwordLockout: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-lockdir: 2019-01-17T11:00:44Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:00:44Z DEBUG nsslapd-certdir: 2019-01-17T11:00:44Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:00:44Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:00:44Z DEBUG 10 2019-01-17T11:00:44Z DEBUG nsslapd-backendconfig: 2019-01-17T11:00:44Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG nsslapd-threadnumber: 2019-01-17T11:00:44Z DEBUG 24 2019-01-17T11:00:44Z DEBUG nsslapd-schemamod: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-localhost: 2019-01-17T11:00:44Z DEBUG centos75.local 2019-01-17T11:00:44Z DEBUG nsslapd-bakdir: 2019-01-17T11:00:44Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:00:44Z DEBUG passwordMin8bit: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:00:44Z DEBUG uidNumber 2019-01-17T11:00:44Z DEBUG nsslapd-validate-cert: 2019-01-17T11:00:44Z DEBUG warn 2019-01-17T11:00:44Z DEBUG passwordMinCategories: 2019-01-17T11:00:44Z DEBUG 3 2019-01-17T11:00:44Z DEBUG passwordMinLowers: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG passwordAdminDN: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG passwordMinSpecials: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:00:44Z DEBUG 100 2019-01-17T11:00:44Z DEBUG nsslapd-lastmod: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:00:44Z DEBUG 40 2019-01-17T11:00:44Z DEBUG passwordMaxRepeats: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:00:44Z DEBUG -1 2019-01-17T11:00:44Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:00:44Z DEBUG none 2019-01-17T11:00:44Z DEBUG nsslapd-result-tweak: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:00:44Z DEBUG month 2019-01-17T11:00:44Z DEBUG passwordUnlock: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-schemacheck: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-maxbersize: 2019-01-17T11:00:44Z DEBUG 209715200 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:00:44Z DEBUG 100 2019-01-17T11:00:44Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:00:44Z DEBUG dc=example,dc=com 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-localssf: 2019-01-17T11:00:44Z DEBUG 71 2019-01-17T11:00:44Z DEBUG nsslapd-sizelimit: 2019-01-17T11:00:44Z DEBUG 2000 2019-01-17T11:00:44Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:00:44Z DEBUG dc=local 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:00:44Z DEBUG 2097152 2019-01-17T11:00:44Z DEBUG passwordLockoutDuration: 2019-01-17T11:00:44Z DEBUG 3600 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-port: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:00:44Z DEBUG 100 2019-01-17T11:00:44Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:00:44Z DEBUG cn=schema 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG cn=monitor 2019-01-17T11:00:44Z DEBUG cn=config 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-auditlog: 2019-01-17T11:00:44Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:00:44Z DEBUG 600 2019-01-17T11:00:44Z DEBUG nsslapd-rootpw: 2019-01-17T11:00:44Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:00:44Z DEBUG 300000 2019-01-17T11:00:44Z DEBUG nsslapd-workingdir: 2019-01-17T11:00:44Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:00:44Z DEBUG 2019-01-17T11:00:44Z DEBUG nsslapd-rundir: 2019-01-17T11:00:44Z DEBUG /var/run/dirsrv 2019-01-17T11:00:44Z DEBUG nsslapd-schemareplace: 2019-01-17T11:00:44Z DEBUG replication-only 2019-01-17T11:00:44Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:00:44Z DEBUG 16384 2019-01-17T11:00:44Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:00:44Z DEBUG 10000 2019-01-17T11:00:44Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG passwordMinDigits: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:00:44Z DEBUG 5 2019-01-17T11:00:44Z DEBUG passwordStorageScheme: 2019-01-17T11:00:44Z DEBUG SSHA512 2019-01-17T11:00:44Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG [] 2019-01-17T11:00:44Z DEBUG Updated 0 2019-01-17T11:00:44Z DEBUG Done 2019-01-17T11:00:44Z DEBUG Updating existing entry: cn=config,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG --------------------------------------------- 2019-01-17T11:00:44Z DEBUG Initial value 2019-01-17T11:00:44Z DEBUG dn: cn=config,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG nsslapd-directory: 2019-01-17T11:00:44Z DEBUG /var/lib/dirsrv/slapd-LOCAL/db 2019-01-17T11:00:44Z DEBUG cn: 2019-01-17T11:00:44Z DEBUG config 2019-01-17T11:00:44Z DEBUG nsslapd-db-transaction-batch-val: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG objectClass: 2019-01-17T11:00:44Z DEBUG top 2019-01-17T11:00:44Z DEBUG extensibleObject 2019-01-17T11:00:44Z DEBUG nsslapd-lookthroughlimit: 2019-01-17T11:00:44Z DEBUG 100000 2019-01-17T11:00:44Z DEBUG nsslapd-db-deadlock-policy: 2019-01-17T11:00:44Z DEBUG 9 2019-01-17T11:00:44Z DEBUG nsslapd-db-transaction-batch-min-wait: 2019-01-17T11:00:44Z DEBUG 50 2019-01-17T11:00:44Z DEBUG nsslapd-db-locks: 2019-01-17T11:00:44Z DEBUG 50000 2019-01-17T11:00:44Z DEBUG nsslapd-serial-lock: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-subtree-rename-switch: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-backend-opt-level: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-db-logdirectory: 2019-01-17T11:00:44Z DEBUG /var/lib/dirsrv/slapd-LOCAL/db 2019-01-17T11:00:44Z DEBUG nsslapd-exclude-from-export: 2019-01-17T11:00:44Z DEBUG entrydn entryid dncomp parentid numSubordinates tombstonenumsubordinates entryusn 2019-01-17T11:00:44Z DEBUG nsslapd-cache-autosize: 2019-01-17T11:00:44Z DEBUG 10 2019-01-17T11:00:44Z DEBUG nsslapd-db-transaction-batch-max-wait: 2019-01-17T11:00:44Z DEBUG 50 2019-01-17T11:00:44Z DEBUG nsslapd-rangelookthroughlimit: 2019-01-17T11:00:44Z DEBUG 5000 2019-01-17T11:00:44Z DEBUG nsslapd-dbcachesize: 2019-01-17T11:00:44Z DEBUG 2419916 2019-01-17T11:00:44Z DEBUG nsslapd-mode: 2019-01-17T11:00:44Z DEBUG 600 2019-01-17T11:00:44Z DEBUG nsslapd-db-logbuf-size: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-import-cache-autosize: 2019-01-17T11:00:44Z DEBUG -1 2019-01-17T11:00:44Z DEBUG nsslapd-search-use-vlv-index: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-pagedidlistscanlimit: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-idlistscanlimit: 2019-01-17T11:00:44Z DEBUG 100000 2019-01-17T11:00:44Z DEBUG nsslapd-search-bypass-filter-test: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-db-compactdb-interval: 2019-01-17T11:00:44Z DEBUG 2592000 2019-01-17T11:00:44Z DEBUG nsslapd-pagedlookthroughlimit: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-idl-switch: 2019-01-17T11:00:44Z DEBUG new 2019-01-17T11:00:44Z DEBUG nsslapd-db-durable-transaction: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-cache-autosize-split: 2019-01-17T11:00:44Z DEBUG 25 2019-01-17T11:00:44Z DEBUG nsslapd-db-private-import-mem: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-db-transaction-wait: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-db-checkpoint-interval: 2019-01-17T11:00:44Z DEBUG 60 2019-01-17T11:00:44Z DEBUG nsslapd-import-cachesize: 2019-01-17T11:00:44Z DEBUG 16777216 2019-01-17T11:00:44Z DEBUG replace: 5000 not found, skipping 2019-01-17T11:00:44Z DEBUG replace: 4000 not found, skipping 2019-01-17T11:00:44Z DEBUG --------------------------------------------- 2019-01-17T11:00:44Z DEBUG Final value after applying updates 2019-01-17T11:00:44Z DEBUG dn: cn=config,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:44Z DEBUG nsslapd-directory: 2019-01-17T11:00:44Z DEBUG /var/lib/dirsrv/slapd-LOCAL/db 2019-01-17T11:00:44Z DEBUG cn: 2019-01-17T11:00:44Z DEBUG config 2019-01-17T11:00:44Z DEBUG nsslapd-db-transaction-batch-val: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG objectClass: 2019-01-17T11:00:44Z DEBUG top 2019-01-17T11:00:44Z DEBUG extensibleObject 2019-01-17T11:00:44Z DEBUG nsslapd-lookthroughlimit: 2019-01-17T11:00:44Z DEBUG 100000 2019-01-17T11:00:44Z DEBUG nsslapd-db-deadlock-policy: 2019-01-17T11:00:44Z DEBUG 9 2019-01-17T11:00:44Z DEBUG nsslapd-db-transaction-batch-min-wait: 2019-01-17T11:00:44Z DEBUG 50 2019-01-17T11:00:44Z DEBUG nsslapd-db-locks: 2019-01-17T11:00:44Z DEBUG 50000 2019-01-17T11:00:44Z DEBUG nsslapd-serial-lock: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-subtree-rename-switch: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-backend-opt-level: 2019-01-17T11:00:44Z DEBUG 1 2019-01-17T11:00:44Z DEBUG nsslapd-db-logdirectory: 2019-01-17T11:00:44Z DEBUG /var/lib/dirsrv/slapd-LOCAL/db 2019-01-17T11:00:44Z DEBUG nsslapd-exclude-from-export: 2019-01-17T11:00:44Z DEBUG entrydn entryid dncomp parentid numSubordinates tombstonenumsubordinates entryusn 2019-01-17T11:00:44Z DEBUG nsslapd-cache-autosize: 2019-01-17T11:00:44Z DEBUG 10 2019-01-17T11:00:44Z DEBUG nsslapd-db-transaction-batch-max-wait: 2019-01-17T11:00:44Z DEBUG 50 2019-01-17T11:00:44Z DEBUG nsslapd-rangelookthroughlimit: 2019-01-17T11:00:44Z DEBUG 5000 2019-01-17T11:00:44Z DEBUG nsslapd-dbcachesize: 2019-01-17T11:00:44Z DEBUG 2419916 2019-01-17T11:00:44Z DEBUG nsslapd-mode: 2019-01-17T11:00:44Z DEBUG 600 2019-01-17T11:00:44Z DEBUG nsslapd-db-logbuf-size: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-import-cache-autosize: 2019-01-17T11:00:44Z DEBUG -1 2019-01-17T11:00:44Z DEBUG nsslapd-search-use-vlv-index: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-pagedidlistscanlimit: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-idlistscanlimit: 2019-01-17T11:00:44Z DEBUG 100000 2019-01-17T11:00:44Z DEBUG nsslapd-search-bypass-filter-test: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-db-compactdb-interval: 2019-01-17T11:00:44Z DEBUG 2592000 2019-01-17T11:00:44Z DEBUG nsslapd-pagedlookthroughlimit: 2019-01-17T11:00:44Z DEBUG 0 2019-01-17T11:00:44Z DEBUG nsslapd-idl-switch: 2019-01-17T11:00:44Z DEBUG new 2019-01-17T11:00:44Z DEBUG nsslapd-db-durable-transaction: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-cache-autosize-split: 2019-01-17T11:00:44Z DEBUG 25 2019-01-17T11:00:44Z DEBUG nsslapd-db-private-import-mem: 2019-01-17T11:00:44Z DEBUG on 2019-01-17T11:00:44Z DEBUG nsslapd-db-transaction-wait: 2019-01-17T11:00:44Z DEBUG off 2019-01-17T11:00:44Z DEBUG nsslapd-db-checkpoint-interval: 2019-01-17T11:00:44Z DEBUG 60 2019-01-17T11:00:44Z DEBUG nsslapd-import-cachesize: 2019-01-17T11:00:44Z DEBUG 16777216 2019-01-17T11:00:44Z DEBUG [] 2019-01-17T11:00:44Z DEBUG Updated 0 2019-01-17T11:00:44Z DEBUG Done 2019-01-17T11:00:44Z DEBUG New entry: cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:00:44Z DEBUG --------------------------------------------- 2019-01-17T11:00:44Z DEBUG Initial value 2019-01-17T11:00:44Z DEBUG dn: cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:00:44Z DEBUG objectclass: 2019-01-17T11:00:44Z DEBUG nsContainer 2019-01-17T11:00:44Z DEBUG top 2019-01-17T11:00:44Z DEBUG nsSizeLimit: 2019-01-17T11:00:44Z DEBUG 5000 2019-01-17T11:00:44Z DEBUG nsLookThroughLimit: 2019-01-17T11:00:44Z DEBUG 5000 2019-01-17T11:00:44Z DEBUG cn: 2019-01-17T11:00:44Z DEBUG anonymous-limits 2019-01-17T11:00:44Z DEBUG --------------------------------------------- 2019-01-17T11:00:44Z DEBUG Final value after applying updates 2019-01-17T11:00:44Z DEBUG dn: cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:00:44Z DEBUG objectclass: 2019-01-17T11:00:44Z DEBUG nsContainer 2019-01-17T11:00:44Z DEBUG top 2019-01-17T11:00:44Z DEBUG nsSizeLimit: 2019-01-17T11:00:44Z DEBUG 5000 2019-01-17T11:00:44Z DEBUG nsLookThroughLimit: 2019-01-17T11:00:44Z DEBUG 5000 2019-01-17T11:00:44Z DEBUG cn: 2019-01-17T11:00:44Z DEBUG anonymous-limits 2019-01-17T11:00:44Z ERROR Parent DN of cn=anonymous-limits,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-betype: 2019-01-17T11:00:45Z DEBUG ldbm database 2019-01-17T11:00:45Z DEBUG nsslapd-nagle: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-referralmode: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:00:45Z DEBUG 64 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 500 2019-01-17T11:00:45Z DEBUG passwordMinAlphas: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-readonly: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordLegacyPolicy: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:00:45Z DEBUG allowed 2019-01-17T11:00:45Z DEBUG passwordMinUppers: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-plugin: 2019-01-17T11:00:45Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:00:45Z DEBUG 20971520 2019-01-17T11:00:45Z DEBUG nsslapd-timelimit: 2019-01-17T11:00:45Z DEBUG 3600 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinTokenLength: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordMinAge: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:00:45Z DEBUG 60 2019-01-17T11:00:45Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:00:45Z DEBUG 1024 2019-01-17T11:00:45Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordInHistory: 2019-01-17T11:00:45Z DEBUG 6 2019-01-17T11:00:45Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-conntablesize: 2019-01-17T11:00:45Z DEBUG 16384 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-saslpath: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG passwordMaxAge: 2019-01-17T11:00:45Z DEBUG 8640000 2019-01-17T11:00:45Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:00:45Z DEBUG gidNumber 2019-01-17T11:00:45Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG day 2019-01-17T11:00:45Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-csnlogging: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-tmpdir: 2019-01-17T11:00:45Z DEBUG /tmp 2019-01-17T11:00:45Z DEBUG passwordResetFailureCount: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-counters: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-svrtab: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-minssf: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-schemadir: 2019-01-17T11:00:45Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:00:45Z DEBUG nsslapd-localuser: 2019-01-17T11:00:45Z DEBUG dirsrv 2019-01-17T11:00:45Z DEBUG nsslapd-security: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordChange: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-port 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:00:45Z DEBUG passwordMaxFailure: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:00:45Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:00:45Z DEBUG 128 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:00:45Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-rootdn: 2019-01-17T11:00:45Z DEBUG cn=Directory Manager 2019-01-17T11:00:45Z DEBUG nsslapd-ldifdir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:00:45Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordMustChange: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordExp: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-logging-backend: 2019-01-17T11:00:45Z DEBUG dirsrv-log 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:45Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:00:45Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:00:45Z DEBUG cn=Directory Manager 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinLength: 2019-01-17T11:00:45Z DEBUG 8 2019-01-17T11:00:45Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-idletimeout: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-securePort: 2019-01-17T11:00:45Z DEBUG 636 2019-01-17T11:00:45Z DEBUG nsslapd-snmp-index: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG config 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapdConfig 2019-01-17T11:00:45Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordSendExpiringTime: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-hash-filters: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:00:45Z DEBUG next 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-listenhost: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordCheckSyntax: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordGraceLimit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG passwordWarning: 2019-01-17T11:00:45Z DEBUG 86400 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-instancedir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-config: 2019-01-17T11:00:45Z DEBUG cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-versionstring: 2019-01-17T11:00:45Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:00:45Z DEBUG 256 2019-01-17T11:00:45Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:00:45Z DEBUG SSHA512 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordLockout: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-lockdir: 2019-01-17T11:00:45Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-certdir: 2019-01-17T11:00:45Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 10 2019-01-17T11:00:45Z DEBUG nsslapd-backendconfig: 2019-01-17T11:00:45Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-threadnumber: 2019-01-17T11:00:45Z DEBUG 24 2019-01-17T11:00:45Z DEBUG nsslapd-schemamod: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-localhost: 2019-01-17T11:00:45Z DEBUG centos75.local 2019-01-17T11:00:45Z DEBUG nsslapd-bakdir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:00:45Z DEBUG passwordMin8bit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:00:45Z DEBUG uidNumber 2019-01-17T11:00:45Z DEBUG nsslapd-validate-cert: 2019-01-17T11:00:45Z DEBUG warn 2019-01-17T11:00:45Z DEBUG passwordMinCategories: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG passwordMinLowers: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordAdminDN: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordMinSpecials: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-lastmod: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:00:45Z DEBUG 40 2019-01-17T11:00:45Z DEBUG passwordMaxRepeats: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:00:45Z DEBUG -1 2019-01-17T11:00:45Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG nsslapd-result-tweak: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG passwordUnlock: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-schemacheck: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-maxbersize: 2019-01-17T11:00:45Z DEBUG 209715200 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:00:45Z DEBUG dc=example,dc=com 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-localssf: 2019-01-17T11:00:45Z DEBUG 71 2019-01-17T11:00:45Z DEBUG nsslapd-sizelimit: 2019-01-17T11:00:45Z DEBUG 2000 2019-01-17T11:00:45Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG passwordLockoutDuration: 2019-01-17T11:00:45Z DEBUG 3600 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-port: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:00:45Z DEBUG cn=schema 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG cn=monitor 2019-01-17T11:00:45Z DEBUG cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-rootpw: 2019-01-17T11:00:45Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:00:45Z DEBUG 300000 2019-01-17T11:00:45Z DEBUG nsslapd-workingdir: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-rundir: 2019-01-17T11:00:45Z DEBUG /var/run/dirsrv 2019-01-17T11:00:45Z DEBUG nsslapd-schemareplace: 2019-01-17T11:00:45Z DEBUG replication-only 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:00:45Z DEBUG 16384 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:00:45Z DEBUG 10000 2019-01-17T11:00:45Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinDigits: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG passwordStorageScheme: 2019-01-17T11:00:45Z DEBUG SSHA512 2019-01-17T11:00:45Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG only: set nsslapd-anonlimitsdn to 'cn=anonymous-limits,cn=etc,dc=local', current value [u'cn=anonymous-limits,cn=etc,dc=local'] 2019-01-17T11:00:45Z DEBUG only: updated value [u'cn=anonymous-limits,cn=etc,dc=local'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-betype: 2019-01-17T11:00:45Z DEBUG ldbm database 2019-01-17T11:00:45Z DEBUG nsslapd-nagle: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-referralmode: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:00:45Z DEBUG 64 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 500 2019-01-17T11:00:45Z DEBUG passwordMinAlphas: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-readonly: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordLegacyPolicy: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:00:45Z DEBUG allowed 2019-01-17T11:00:45Z DEBUG passwordMinUppers: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-plugin: 2019-01-17T11:00:45Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:00:45Z DEBUG 20971520 2019-01-17T11:00:45Z DEBUG nsslapd-timelimit: 2019-01-17T11:00:45Z DEBUG 3600 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinTokenLength: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordMinAge: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:00:45Z DEBUG 60 2019-01-17T11:00:45Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:00:45Z DEBUG 1024 2019-01-17T11:00:45Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordInHistory: 2019-01-17T11:00:45Z DEBUG 6 2019-01-17T11:00:45Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-conntablesize: 2019-01-17T11:00:45Z DEBUG 16384 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-saslpath: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG passwordMaxAge: 2019-01-17T11:00:45Z DEBUG 8640000 2019-01-17T11:00:45Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:00:45Z DEBUG gidNumber 2019-01-17T11:00:45Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG day 2019-01-17T11:00:45Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-csnlogging: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-tmpdir: 2019-01-17T11:00:45Z DEBUG /tmp 2019-01-17T11:00:45Z DEBUG passwordResetFailureCount: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-counters: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-svrtab: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-minssf: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-schemadir: 2019-01-17T11:00:45Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:00:45Z DEBUG nsslapd-localuser: 2019-01-17T11:00:45Z DEBUG dirsrv 2019-01-17T11:00:45Z DEBUG nsslapd-security: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordChange: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-port 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:00:45Z DEBUG passwordMaxFailure: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:00:45Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:00:45Z DEBUG 128 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:00:45Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-rootdn: 2019-01-17T11:00:45Z DEBUG cn=Directory Manager 2019-01-17T11:00:45Z DEBUG nsslapd-ldifdir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:00:45Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordMustChange: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordExp: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-logging-backend: 2019-01-17T11:00:45Z DEBUG dirsrv-log 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:45Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:00:45Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:00:45Z DEBUG cn=Directory Manager 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinLength: 2019-01-17T11:00:45Z DEBUG 8 2019-01-17T11:00:45Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-idletimeout: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-securePort: 2019-01-17T11:00:45Z DEBUG 636 2019-01-17T11:00:45Z DEBUG nsslapd-snmp-index: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG config 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapdConfig 2019-01-17T11:00:45Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordSendExpiringTime: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-hash-filters: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:00:45Z DEBUG next 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-listenhost: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordCheckSyntax: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordGraceLimit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG passwordWarning: 2019-01-17T11:00:45Z DEBUG 86400 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-instancedir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-config: 2019-01-17T11:00:45Z DEBUG cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-versionstring: 2019-01-17T11:00:45Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:00:45Z DEBUG 256 2019-01-17T11:00:45Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:00:45Z DEBUG SSHA512 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordLockout: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-lockdir: 2019-01-17T11:00:45Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-certdir: 2019-01-17T11:00:45Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 10 2019-01-17T11:00:45Z DEBUG nsslapd-backendconfig: 2019-01-17T11:00:45Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-threadnumber: 2019-01-17T11:00:45Z DEBUG 24 2019-01-17T11:00:45Z DEBUG nsslapd-schemamod: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-localhost: 2019-01-17T11:00:45Z DEBUG centos75.local 2019-01-17T11:00:45Z DEBUG nsslapd-bakdir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:00:45Z DEBUG passwordMin8bit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:00:45Z DEBUG uidNumber 2019-01-17T11:00:45Z DEBUG nsslapd-validate-cert: 2019-01-17T11:00:45Z DEBUG warn 2019-01-17T11:00:45Z DEBUG passwordMinCategories: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG passwordMinLowers: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordAdminDN: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordMinSpecials: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-lastmod: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:00:45Z DEBUG 40 2019-01-17T11:00:45Z DEBUG passwordMaxRepeats: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:00:45Z DEBUG -1 2019-01-17T11:00:45Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG nsslapd-result-tweak: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG passwordUnlock: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-schemacheck: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-maxbersize: 2019-01-17T11:00:45Z DEBUG 209715200 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:00:45Z DEBUG dc=example,dc=com 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-localssf: 2019-01-17T11:00:45Z DEBUG 71 2019-01-17T11:00:45Z DEBUG nsslapd-sizelimit: 2019-01-17T11:00:45Z DEBUG 2000 2019-01-17T11:00:45Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG passwordLockoutDuration: 2019-01-17T11:00:45Z DEBUG 3600 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-port: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:00:45Z DEBUG cn=schema 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG cn=monitor 2019-01-17T11:00:45Z DEBUG cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-rootpw: 2019-01-17T11:00:45Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:00:45Z DEBUG 300000 2019-01-17T11:00:45Z DEBUG nsslapd-workingdir: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-rundir: 2019-01-17T11:00:45Z DEBUG /var/run/dirsrv 2019-01-17T11:00:45Z DEBUG nsslapd-schemareplace: 2019-01-17T11:00:45Z DEBUG replication-only 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:00:45Z DEBUG 16384 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:00:45Z DEBUG 10000 2019-01-17T11:00:45Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinDigits: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG passwordStorageScheme: 2019-01-17T11:00:45Z DEBUG SSHA512 2019-01-17T11:00:45Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-betype: 2019-01-17T11:00:45Z DEBUG ldbm database 2019-01-17T11:00:45Z DEBUG nsslapd-nagle: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-referralmode: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:00:45Z DEBUG 64 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 500 2019-01-17T11:00:45Z DEBUG passwordMinAlphas: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-readonly: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordLegacyPolicy: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:00:45Z DEBUG allowed 2019-01-17T11:00:45Z DEBUG passwordMinUppers: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-plugin: 2019-01-17T11:00:45Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:00:45Z DEBUG 20971520 2019-01-17T11:00:45Z DEBUG nsslapd-timelimit: 2019-01-17T11:00:45Z DEBUG 3600 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinTokenLength: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordMinAge: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:00:45Z DEBUG 60 2019-01-17T11:00:45Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:00:45Z DEBUG 1024 2019-01-17T11:00:45Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordInHistory: 2019-01-17T11:00:45Z DEBUG 6 2019-01-17T11:00:45Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-conntablesize: 2019-01-17T11:00:45Z DEBUG 16384 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-saslpath: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG passwordMaxAge: 2019-01-17T11:00:45Z DEBUG 8640000 2019-01-17T11:00:45Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:00:45Z DEBUG gidNumber 2019-01-17T11:00:45Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG day 2019-01-17T11:00:45Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-csnlogging: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-tmpdir: 2019-01-17T11:00:45Z DEBUG /tmp 2019-01-17T11:00:45Z DEBUG passwordResetFailureCount: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-counters: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-svrtab: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-minssf: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-schemadir: 2019-01-17T11:00:45Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:00:45Z DEBUG nsslapd-localuser: 2019-01-17T11:00:45Z DEBUG dirsrv 2019-01-17T11:00:45Z DEBUG nsslapd-security: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordChange: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-port 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:00:45Z DEBUG passwordMaxFailure: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:00:45Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:00:45Z DEBUG 128 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:00:45Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-rootdn: 2019-01-17T11:00:45Z DEBUG cn=Directory Manager 2019-01-17T11:00:45Z DEBUG nsslapd-ldifdir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:00:45Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordMustChange: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordExp: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-logging-backend: 2019-01-17T11:00:45Z DEBUG dirsrv-log 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:45Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:00:45Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:00:45Z DEBUG cn=Directory Manager 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinLength: 2019-01-17T11:00:45Z DEBUG 8 2019-01-17T11:00:45Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-idletimeout: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-securePort: 2019-01-17T11:00:45Z DEBUG 636 2019-01-17T11:00:45Z DEBUG nsslapd-snmp-index: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG config 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapdConfig 2019-01-17T11:00:45Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordSendExpiringTime: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-hash-filters: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:00:45Z DEBUG next 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-listenhost: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordCheckSyntax: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordGraceLimit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG passwordWarning: 2019-01-17T11:00:45Z DEBUG 86400 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-instancedir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-config: 2019-01-17T11:00:45Z DEBUG cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-versionstring: 2019-01-17T11:00:45Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:00:45Z DEBUG 256 2019-01-17T11:00:45Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:00:45Z DEBUG SSHA512 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordLockout: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-lockdir: 2019-01-17T11:00:45Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-certdir: 2019-01-17T11:00:45Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 10 2019-01-17T11:00:45Z DEBUG nsslapd-backendconfig: 2019-01-17T11:00:45Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-threadnumber: 2019-01-17T11:00:45Z DEBUG 24 2019-01-17T11:00:45Z DEBUG nsslapd-schemamod: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-localhost: 2019-01-17T11:00:45Z DEBUG centos75.local 2019-01-17T11:00:45Z DEBUG nsslapd-bakdir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:00:45Z DEBUG passwordMin8bit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:00:45Z DEBUG uidNumber 2019-01-17T11:00:45Z DEBUG nsslapd-validate-cert: 2019-01-17T11:00:45Z DEBUG warn 2019-01-17T11:00:45Z DEBUG passwordMinCategories: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG passwordMinLowers: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordAdminDN: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordMinSpecials: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-lastmod: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:00:45Z DEBUG 40 2019-01-17T11:00:45Z DEBUG passwordMaxRepeats: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:00:45Z DEBUG -1 2019-01-17T11:00:45Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG nsslapd-result-tweak: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG passwordUnlock: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-schemacheck: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-maxbersize: 2019-01-17T11:00:45Z DEBUG 209715200 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:00:45Z DEBUG dc=example,dc=com 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-localssf: 2019-01-17T11:00:45Z DEBUG 71 2019-01-17T11:00:45Z DEBUG nsslapd-sizelimit: 2019-01-17T11:00:45Z DEBUG 2000 2019-01-17T11:00:45Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG passwordLockoutDuration: 2019-01-17T11:00:45Z DEBUG 3600 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-port: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:00:45Z DEBUG cn=schema 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG cn=monitor 2019-01-17T11:00:45Z DEBUG cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-rootpw: 2019-01-17T11:00:45Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:00:45Z DEBUG 300000 2019-01-17T11:00:45Z DEBUG nsslapd-workingdir: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-rundir: 2019-01-17T11:00:45Z DEBUG /var/run/dirsrv 2019-01-17T11:00:45Z DEBUG nsslapd-schemareplace: 2019-01-17T11:00:45Z DEBUG replication-only 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:00:45Z DEBUG 16384 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:00:45Z DEBUG 10000 2019-01-17T11:00:45Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinDigits: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG passwordStorageScheme: 2019-01-17T11:00:45Z DEBUG SSHA512 2019-01-17T11:00:45Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG add: 'dc=local' to nsslapd-defaultNamingContext, current value [u'dc=local'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'dc=local'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-betype: 2019-01-17T11:00:45Z DEBUG ldbm database 2019-01-17T11:00:45Z DEBUG nsslapd-nagle: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-referralmode: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:00:45Z DEBUG 64 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 500 2019-01-17T11:00:45Z DEBUG passwordMinAlphas: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-readonly: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordLegacyPolicy: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:00:45Z DEBUG allowed 2019-01-17T11:00:45Z DEBUG passwordMinUppers: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-plugin: 2019-01-17T11:00:45Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:00:45Z DEBUG 20971520 2019-01-17T11:00:45Z DEBUG nsslapd-timelimit: 2019-01-17T11:00:45Z DEBUG 3600 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinTokenLength: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordMinAge: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:00:45Z DEBUG 60 2019-01-17T11:00:45Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:00:45Z DEBUG 1024 2019-01-17T11:00:45Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordInHistory: 2019-01-17T11:00:45Z DEBUG 6 2019-01-17T11:00:45Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-conntablesize: 2019-01-17T11:00:45Z DEBUG 16384 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-saslpath: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG passwordMaxAge: 2019-01-17T11:00:45Z DEBUG 8640000 2019-01-17T11:00:45Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:00:45Z DEBUG gidNumber 2019-01-17T11:00:45Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG day 2019-01-17T11:00:45Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-csnlogging: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-tmpdir: 2019-01-17T11:00:45Z DEBUG /tmp 2019-01-17T11:00:45Z DEBUG passwordResetFailureCount: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-counters: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-svrtab: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-minssf: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-schemadir: 2019-01-17T11:00:45Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:00:45Z DEBUG nsslapd-localuser: 2019-01-17T11:00:45Z DEBUG dirsrv 2019-01-17T11:00:45Z DEBUG nsslapd-security: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordChange: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-port 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:00:45Z DEBUG passwordMaxFailure: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:00:45Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:00:45Z DEBUG 128 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:00:45Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-rootdn: 2019-01-17T11:00:45Z DEBUG cn=Directory Manager 2019-01-17T11:00:45Z DEBUG nsslapd-ldifdir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:00:45Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordMustChange: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordExp: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-logging-backend: 2019-01-17T11:00:45Z DEBUG dirsrv-log 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:45Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:00:45Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:00:45Z DEBUG cn=Directory Manager 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinLength: 2019-01-17T11:00:45Z DEBUG 8 2019-01-17T11:00:45Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-idletimeout: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-securePort: 2019-01-17T11:00:45Z DEBUG 636 2019-01-17T11:00:45Z DEBUG nsslapd-snmp-index: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG config 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapdConfig 2019-01-17T11:00:45Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordSendExpiringTime: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-hash-filters: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:00:45Z DEBUG next 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-listenhost: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordCheckSyntax: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordGraceLimit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG passwordWarning: 2019-01-17T11:00:45Z DEBUG 86400 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-instancedir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-config: 2019-01-17T11:00:45Z DEBUG cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-versionstring: 2019-01-17T11:00:45Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:00:45Z DEBUG 256 2019-01-17T11:00:45Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:00:45Z DEBUG SSHA512 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordLockout: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-lockdir: 2019-01-17T11:00:45Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-certdir: 2019-01-17T11:00:45Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 10 2019-01-17T11:00:45Z DEBUG nsslapd-backendconfig: 2019-01-17T11:00:45Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-threadnumber: 2019-01-17T11:00:45Z DEBUG 24 2019-01-17T11:00:45Z DEBUG nsslapd-schemamod: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-localhost: 2019-01-17T11:00:45Z DEBUG centos75.local 2019-01-17T11:00:45Z DEBUG nsslapd-bakdir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:00:45Z DEBUG passwordMin8bit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:00:45Z DEBUG uidNumber 2019-01-17T11:00:45Z DEBUG nsslapd-validate-cert: 2019-01-17T11:00:45Z DEBUG warn 2019-01-17T11:00:45Z DEBUG passwordMinCategories: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG passwordMinLowers: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordAdminDN: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordMinSpecials: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-lastmod: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:00:45Z DEBUG 40 2019-01-17T11:00:45Z DEBUG passwordMaxRepeats: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:00:45Z DEBUG -1 2019-01-17T11:00:45Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG nsslapd-result-tweak: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG passwordUnlock: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-schemacheck: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-maxbersize: 2019-01-17T11:00:45Z DEBUG 209715200 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:00:45Z DEBUG dc=example,dc=com 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-localssf: 2019-01-17T11:00:45Z DEBUG 71 2019-01-17T11:00:45Z DEBUG nsslapd-sizelimit: 2019-01-17T11:00:45Z DEBUG 2000 2019-01-17T11:00:45Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG passwordLockoutDuration: 2019-01-17T11:00:45Z DEBUG 3600 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-port: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:00:45Z DEBUG cn=schema 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG cn=monitor 2019-01-17T11:00:45Z DEBUG cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-rootpw: 2019-01-17T11:00:45Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:00:45Z DEBUG 300000 2019-01-17T11:00:45Z DEBUG nsslapd-workingdir: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-rundir: 2019-01-17T11:00:45Z DEBUG /var/run/dirsrv 2019-01-17T11:00:45Z DEBUG nsslapd-schemareplace: 2019-01-17T11:00:45Z DEBUG replication-only 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:00:45Z DEBUG 16384 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:00:45Z DEBUG 10000 2019-01-17T11:00:45Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinDigits: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG passwordStorageScheme: 2019-01-17T11:00:45Z DEBUG SSHA512 2019-01-17T11:00:45Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-betype: 2019-01-17T11:00:45Z DEBUG ldbm database 2019-01-17T11:00:45Z DEBUG nsslapd-nagle: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-referralmode: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:00:45Z DEBUG 64 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 500 2019-01-17T11:00:45Z DEBUG passwordMinAlphas: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-readonly: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordLegacyPolicy: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:00:45Z DEBUG allowed 2019-01-17T11:00:45Z DEBUG passwordMinUppers: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-plugin: 2019-01-17T11:00:45Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:00:45Z DEBUG 20971520 2019-01-17T11:00:45Z DEBUG nsslapd-timelimit: 2019-01-17T11:00:45Z DEBUG 3600 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinTokenLength: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordMinAge: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:00:45Z DEBUG 60 2019-01-17T11:00:45Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:00:45Z DEBUG 1024 2019-01-17T11:00:45Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordInHistory: 2019-01-17T11:00:45Z DEBUG 6 2019-01-17T11:00:45Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-conntablesize: 2019-01-17T11:00:45Z DEBUG 16384 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-saslpath: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG passwordMaxAge: 2019-01-17T11:00:45Z DEBUG 8640000 2019-01-17T11:00:45Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:00:45Z DEBUG gidNumber 2019-01-17T11:00:45Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG day 2019-01-17T11:00:45Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-csnlogging: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-tmpdir: 2019-01-17T11:00:45Z DEBUG /tmp 2019-01-17T11:00:45Z DEBUG passwordResetFailureCount: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-counters: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-svrtab: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-minssf: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-schemadir: 2019-01-17T11:00:45Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:00:45Z DEBUG nsslapd-localuser: 2019-01-17T11:00:45Z DEBUG dirsrv 2019-01-17T11:00:45Z DEBUG nsslapd-security: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordChange: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-port 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:00:45Z DEBUG passwordMaxFailure: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:00:45Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:00:45Z DEBUG 128 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:00:45Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-rootdn: 2019-01-17T11:00:45Z DEBUG cn=Directory Manager 2019-01-17T11:00:45Z DEBUG nsslapd-ldifdir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:00:45Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordMustChange: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordExp: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-logging-backend: 2019-01-17T11:00:45Z DEBUG dirsrv-log 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:45Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:00:45Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:00:45Z DEBUG cn=Directory Manager 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinLength: 2019-01-17T11:00:45Z DEBUG 8 2019-01-17T11:00:45Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-idletimeout: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-securePort: 2019-01-17T11:00:45Z DEBUG 636 2019-01-17T11:00:45Z DEBUG nsslapd-snmp-index: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG config 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapdConfig 2019-01-17T11:00:45Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordSendExpiringTime: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-hash-filters: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:00:45Z DEBUG next 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-listenhost: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordCheckSyntax: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordGraceLimit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG passwordWarning: 2019-01-17T11:00:45Z DEBUG 86400 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-instancedir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-config: 2019-01-17T11:00:45Z DEBUG cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-versionstring: 2019-01-17T11:00:45Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:00:45Z DEBUG 256 2019-01-17T11:00:45Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:00:45Z DEBUG SSHA512 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordLockout: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-lockdir: 2019-01-17T11:00:45Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-certdir: 2019-01-17T11:00:45Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 10 2019-01-17T11:00:45Z DEBUG nsslapd-backendconfig: 2019-01-17T11:00:45Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-threadnumber: 2019-01-17T11:00:45Z DEBUG 24 2019-01-17T11:00:45Z DEBUG nsslapd-schemamod: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-localhost: 2019-01-17T11:00:45Z DEBUG centos75.local 2019-01-17T11:00:45Z DEBUG nsslapd-bakdir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:00:45Z DEBUG passwordMin8bit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:00:45Z DEBUG uidNumber 2019-01-17T11:00:45Z DEBUG nsslapd-validate-cert: 2019-01-17T11:00:45Z DEBUG warn 2019-01-17T11:00:45Z DEBUG passwordMinCategories: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG passwordMinLowers: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordAdminDN: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordMinSpecials: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-lastmod: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:00:45Z DEBUG 40 2019-01-17T11:00:45Z DEBUG passwordMaxRepeats: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:00:45Z DEBUG -1 2019-01-17T11:00:45Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG nsslapd-result-tweak: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG passwordUnlock: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-schemacheck: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-maxbersize: 2019-01-17T11:00:45Z DEBUG 209715200 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:00:45Z DEBUG dc=example,dc=com 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-localssf: 2019-01-17T11:00:45Z DEBUG 71 2019-01-17T11:00:45Z DEBUG nsslapd-sizelimit: 2019-01-17T11:00:45Z DEBUG 2000 2019-01-17T11:00:45Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG passwordLockoutDuration: 2019-01-17T11:00:45Z DEBUG 3600 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-port: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:00:45Z DEBUG cn=schema 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG cn=monitor 2019-01-17T11:00:45Z DEBUG cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-rootpw: 2019-01-17T11:00:45Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:00:45Z DEBUG 300000 2019-01-17T11:00:45Z DEBUG nsslapd-workingdir: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-rundir: 2019-01-17T11:00:45Z DEBUG /var/run/dirsrv 2019-01-17T11:00:45Z DEBUG nsslapd-schemareplace: 2019-01-17T11:00:45Z DEBUG replication-only 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:00:45Z DEBUG 16384 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:00:45Z DEBUG 10000 2019-01-17T11:00:45Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinDigits: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG passwordStorageScheme: 2019-01-17T11:00:45Z DEBUG SSHA512 2019-01-17T11:00:45Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG only: set nsslapd-minssf-exclude-rootdse to 'on', current value [u'on'] 2019-01-17T11:00:45Z DEBUG only: updated value [u'on'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-betype: 2019-01-17T11:00:45Z DEBUG ldbm database 2019-01-17T11:00:45Z DEBUG nsslapd-nagle: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-referralmode: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:00:45Z DEBUG 64 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 500 2019-01-17T11:00:45Z DEBUG passwordMinAlphas: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-readonly: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordLegacyPolicy: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:00:45Z DEBUG allowed 2019-01-17T11:00:45Z DEBUG passwordMinUppers: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-plugin: 2019-01-17T11:00:45Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:00:45Z DEBUG 20971520 2019-01-17T11:00:45Z DEBUG nsslapd-timelimit: 2019-01-17T11:00:45Z DEBUG 3600 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinTokenLength: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordMinAge: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:00:45Z DEBUG 60 2019-01-17T11:00:45Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:00:45Z DEBUG 1024 2019-01-17T11:00:45Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordInHistory: 2019-01-17T11:00:45Z DEBUG 6 2019-01-17T11:00:45Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-conntablesize: 2019-01-17T11:00:45Z DEBUG 16384 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-saslpath: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG passwordMaxAge: 2019-01-17T11:00:45Z DEBUG 8640000 2019-01-17T11:00:45Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:00:45Z DEBUG gidNumber 2019-01-17T11:00:45Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG day 2019-01-17T11:00:45Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-csnlogging: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-tmpdir: 2019-01-17T11:00:45Z DEBUG /tmp 2019-01-17T11:00:45Z DEBUG passwordResetFailureCount: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-counters: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-svrtab: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-minssf: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-schemadir: 2019-01-17T11:00:45Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:00:45Z DEBUG nsslapd-localuser: 2019-01-17T11:00:45Z DEBUG dirsrv 2019-01-17T11:00:45Z DEBUG nsslapd-security: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordChange: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-port 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:00:45Z DEBUG passwordMaxFailure: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:00:45Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:00:45Z DEBUG 128 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:00:45Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-rootdn: 2019-01-17T11:00:45Z DEBUG cn=Directory Manager 2019-01-17T11:00:45Z DEBUG nsslapd-ldifdir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:00:45Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordMustChange: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordExp: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-logging-backend: 2019-01-17T11:00:45Z DEBUG dirsrv-log 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:45Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:00:45Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:00:45Z DEBUG cn=Directory Manager 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinLength: 2019-01-17T11:00:45Z DEBUG 8 2019-01-17T11:00:45Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-idletimeout: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-securePort: 2019-01-17T11:00:45Z DEBUG 636 2019-01-17T11:00:45Z DEBUG nsslapd-snmp-index: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG config 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapdConfig 2019-01-17T11:00:45Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordSendExpiringTime: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-hash-filters: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:00:45Z DEBUG next 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-listenhost: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordCheckSyntax: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordGraceLimit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG passwordWarning: 2019-01-17T11:00:45Z DEBUG 86400 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-instancedir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-config: 2019-01-17T11:00:45Z DEBUG cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-versionstring: 2019-01-17T11:00:45Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:00:45Z DEBUG 256 2019-01-17T11:00:45Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:00:45Z DEBUG SSHA512 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordLockout: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-lockdir: 2019-01-17T11:00:45Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-certdir: 2019-01-17T11:00:45Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 10 2019-01-17T11:00:45Z DEBUG nsslapd-backendconfig: 2019-01-17T11:00:45Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-threadnumber: 2019-01-17T11:00:45Z DEBUG 24 2019-01-17T11:00:45Z DEBUG nsslapd-schemamod: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-localhost: 2019-01-17T11:00:45Z DEBUG centos75.local 2019-01-17T11:00:45Z DEBUG nsslapd-bakdir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:00:45Z DEBUG passwordMin8bit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:00:45Z DEBUG uidNumber 2019-01-17T11:00:45Z DEBUG nsslapd-validate-cert: 2019-01-17T11:00:45Z DEBUG warn 2019-01-17T11:00:45Z DEBUG passwordMinCategories: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG passwordMinLowers: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordAdminDN: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordMinSpecials: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-lastmod: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:00:45Z DEBUG 40 2019-01-17T11:00:45Z DEBUG passwordMaxRepeats: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:00:45Z DEBUG -1 2019-01-17T11:00:45Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG nsslapd-result-tweak: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG passwordUnlock: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-schemacheck: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-maxbersize: 2019-01-17T11:00:45Z DEBUG 209715200 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:00:45Z DEBUG dc=example,dc=com 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-localssf: 2019-01-17T11:00:45Z DEBUG 71 2019-01-17T11:00:45Z DEBUG nsslapd-sizelimit: 2019-01-17T11:00:45Z DEBUG 2000 2019-01-17T11:00:45Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG passwordLockoutDuration: 2019-01-17T11:00:45Z DEBUG 3600 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-port: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:00:45Z DEBUG cn=schema 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG cn=monitor 2019-01-17T11:00:45Z DEBUG cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-rootpw: 2019-01-17T11:00:45Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:00:45Z DEBUG 300000 2019-01-17T11:00:45Z DEBUG nsslapd-workingdir: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-rundir: 2019-01-17T11:00:45Z DEBUG /var/run/dirsrv 2019-01-17T11:00:45Z DEBUG nsslapd-schemareplace: 2019-01-17T11:00:45Z DEBUG replication-only 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:00:45Z DEBUG 16384 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:00:45Z DEBUG 10000 2019-01-17T11:00:45Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinDigits: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG passwordStorageScheme: 2019-01-17T11:00:45Z DEBUG SSHA512 2019-01-17T11:00:45Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=ipa-winsync,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=ipa-winsync,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG ipa-winsync 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG ipawinsynchomedirattr: 2019-01-17T11:00:45Z DEBUG ipaHomesRootDir 2019-01-17T11:00:45Z DEBUG ipawinsyncnewuserocattr: 2019-01-17T11:00:45Z DEBUG ipauserobjectclasses 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libipa_winsync 2019-01-17T11:00:45Z DEBUG ipawinsyncuserflatten: 2019-01-17T11:00:45Z DEBUG true 2019-01-17T11:00:45Z DEBUG ipawinsyncdefaultgroupfilter: 2019-01-17T11:00:45Z DEBUG (gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames) 2019-01-17T11:00:45Z DEBUG ipawinsyncforcesync: 2019-01-17T11:00:45Z DEBUG true 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG FreeIPA/1.0 2019-01-17T11:00:45Z DEBUG ipawinsyncrealmattr: 2019-01-17T11:00:45Z DEBUG cn 2019-01-17T11:00:45Z DEBUG ipawinsyncacctdisable: 2019-01-17T11:00:45Z DEBUG both 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG ipa_winsync_plugin_init 2019-01-17T11:00:45Z DEBUG ipawinsyncnewentryfilter: 2019-01-17T11:00:45Z DEBUG (cn=ipaConfig) 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG FreeIPA project 2019-01-17T11:00:45Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:00:45Z DEBUG 60 2019-01-17T11:00:45Z DEBUG ipawinsyncdefaultgroupattr: 2019-01-17T11:00:45Z DEBUG ipaDefaultPrimaryGroup 2019-01-17T11:00:45Z DEBUG ipawinsyncrealmfilter: 2019-01-17T11:00:45Z DEBUG (objectclass=krbRealmContainer) 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG preoperation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG ipa winsync plugin 2019-01-17T11:00:45Z DEBUG ipawinsyncloginshellattr: 2019-01-17T11:00:45Z DEBUG ipaDefaultLoginShell 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG ipa-winsync-plugin 2019-01-17T11:00:45Z DEBUG ipawinsyncuserattr: 2019-01-17T11:00:45Z DEBUG uidNumber -1 2019-01-17T11:00:45Z DEBUG gidNumber -1 2019-01-17T11:00:45Z DEBUG only: set nsslapd-pluginPrecedence to '60', current value [u'60'] 2019-01-17T11:00:45Z DEBUG only: updated value [u'60'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=ipa-winsync,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG ipa-winsync 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG ipawinsynchomedirattr: 2019-01-17T11:00:45Z DEBUG ipaHomesRootDir 2019-01-17T11:00:45Z DEBUG ipawinsyncnewuserocattr: 2019-01-17T11:00:45Z DEBUG ipauserobjectclasses 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libipa_winsync 2019-01-17T11:00:45Z DEBUG ipawinsyncuserflatten: 2019-01-17T11:00:45Z DEBUG true 2019-01-17T11:00:45Z DEBUG ipawinsyncdefaultgroupfilter: 2019-01-17T11:00:45Z DEBUG (gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames) 2019-01-17T11:00:45Z DEBUG ipawinsyncforcesync: 2019-01-17T11:00:45Z DEBUG true 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG FreeIPA/1.0 2019-01-17T11:00:45Z DEBUG ipawinsyncrealmattr: 2019-01-17T11:00:45Z DEBUG cn 2019-01-17T11:00:45Z DEBUG ipawinsyncacctdisable: 2019-01-17T11:00:45Z DEBUG both 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG ipa_winsync_plugin_init 2019-01-17T11:00:45Z DEBUG ipawinsyncnewentryfilter: 2019-01-17T11:00:45Z DEBUG (cn=ipaConfig) 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG FreeIPA project 2019-01-17T11:00:45Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:00:45Z DEBUG 60 2019-01-17T11:00:45Z DEBUG ipawinsyncdefaultgroupattr: 2019-01-17T11:00:45Z DEBUG ipaDefaultPrimaryGroup 2019-01-17T11:00:45Z DEBUG ipawinsyncrealmfilter: 2019-01-17T11:00:45Z DEBUG (objectclass=krbRealmContainer) 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG preoperation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG ipa winsync plugin 2019-01-17T11:00:45Z DEBUG ipawinsyncloginshellattr: 2019-01-17T11:00:45Z DEBUG ipaDefaultLoginShell 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG ipa-winsync-plugin 2019-01-17T11:00:45Z DEBUG ipawinsyncuserattr: 2019-01-17T11:00:45Z DEBUG uidNumber -1 2019-01-17T11:00:45Z DEBUG gidNumber -1 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-betype: 2019-01-17T11:00:45Z DEBUG ldbm database 2019-01-17T11:00:45Z DEBUG nsslapd-nagle: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-referralmode: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:00:45Z DEBUG 64 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 500 2019-01-17T11:00:45Z DEBUG passwordMinAlphas: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-readonly: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordLegacyPolicy: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:00:45Z DEBUG allowed 2019-01-17T11:00:45Z DEBUG passwordMinUppers: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-plugin: 2019-01-17T11:00:45Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:00:45Z DEBUG 20971520 2019-01-17T11:00:45Z DEBUG nsslapd-timelimit: 2019-01-17T11:00:45Z DEBUG 3600 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinTokenLength: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordMinAge: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:00:45Z DEBUG 60 2019-01-17T11:00:45Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:00:45Z DEBUG 1024 2019-01-17T11:00:45Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordInHistory: 2019-01-17T11:00:45Z DEBUG 6 2019-01-17T11:00:45Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-conntablesize: 2019-01-17T11:00:45Z DEBUG 16384 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-saslpath: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG passwordMaxAge: 2019-01-17T11:00:45Z DEBUG 8640000 2019-01-17T11:00:45Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:00:45Z DEBUG gidNumber 2019-01-17T11:00:45Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG day 2019-01-17T11:00:45Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-csnlogging: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-tmpdir: 2019-01-17T11:00:45Z DEBUG /tmp 2019-01-17T11:00:45Z DEBUG passwordResetFailureCount: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-counters: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-svrtab: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-minssf: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-schemadir: 2019-01-17T11:00:45Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:00:45Z DEBUG nsslapd-localuser: 2019-01-17T11:00:45Z DEBUG dirsrv 2019-01-17T11:00:45Z DEBUG nsslapd-security: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordChange: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-port 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:00:45Z DEBUG passwordMaxFailure: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:00:45Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:00:45Z DEBUG 128 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:00:45Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-rootdn: 2019-01-17T11:00:45Z DEBUG cn=Directory Manager 2019-01-17T11:00:45Z DEBUG nsslapd-ldifdir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:00:45Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordMustChange: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordExp: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-logging-backend: 2019-01-17T11:00:45Z DEBUG dirsrv-log 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:45Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:00:45Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:00:45Z DEBUG cn=Directory Manager 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinLength: 2019-01-17T11:00:45Z DEBUG 8 2019-01-17T11:00:45Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-idletimeout: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-securePort: 2019-01-17T11:00:45Z DEBUG 636 2019-01-17T11:00:45Z DEBUG nsslapd-snmp-index: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG config 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapdConfig 2019-01-17T11:00:45Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordSendExpiringTime: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-hash-filters: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:00:45Z DEBUG next 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-listenhost: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordCheckSyntax: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordGraceLimit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG passwordWarning: 2019-01-17T11:00:45Z DEBUG 86400 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-instancedir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-config: 2019-01-17T11:00:45Z DEBUG cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-versionstring: 2019-01-17T11:00:45Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:00:45Z DEBUG 256 2019-01-17T11:00:45Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:00:45Z DEBUG SSHA512 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordLockout: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-lockdir: 2019-01-17T11:00:45Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-certdir: 2019-01-17T11:00:45Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 10 2019-01-17T11:00:45Z DEBUG nsslapd-backendconfig: 2019-01-17T11:00:45Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-threadnumber: 2019-01-17T11:00:45Z DEBUG 24 2019-01-17T11:00:45Z DEBUG nsslapd-schemamod: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-localhost: 2019-01-17T11:00:45Z DEBUG centos75.local 2019-01-17T11:00:45Z DEBUG nsslapd-bakdir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:00:45Z DEBUG passwordMin8bit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:00:45Z DEBUG uidNumber 2019-01-17T11:00:45Z DEBUG nsslapd-validate-cert: 2019-01-17T11:00:45Z DEBUG warn 2019-01-17T11:00:45Z DEBUG passwordMinCategories: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG passwordMinLowers: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordAdminDN: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordMinSpecials: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-lastmod: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:00:45Z DEBUG 40 2019-01-17T11:00:45Z DEBUG passwordMaxRepeats: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:00:45Z DEBUG -1 2019-01-17T11:00:45Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG nsslapd-result-tweak: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG passwordUnlock: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-schemacheck: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-maxbersize: 2019-01-17T11:00:45Z DEBUG 209715200 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:00:45Z DEBUG dc=example,dc=com 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-localssf: 2019-01-17T11:00:45Z DEBUG 71 2019-01-17T11:00:45Z DEBUG nsslapd-sizelimit: 2019-01-17T11:00:45Z DEBUG 2000 2019-01-17T11:00:45Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG passwordLockoutDuration: 2019-01-17T11:00:45Z DEBUG 3600 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-port: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:00:45Z DEBUG cn=schema 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG cn=monitor 2019-01-17T11:00:45Z DEBUG cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-rootpw: 2019-01-17T11:00:45Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:00:45Z DEBUG 300000 2019-01-17T11:00:45Z DEBUG nsslapd-workingdir: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-rundir: 2019-01-17T11:00:45Z DEBUG /var/run/dirsrv 2019-01-17T11:00:45Z DEBUG nsslapd-schemareplace: 2019-01-17T11:00:45Z DEBUG replication-only 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:00:45Z DEBUG 16384 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:00:45Z DEBUG 10000 2019-01-17T11:00:45Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinDigits: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG passwordStorageScheme: 2019-01-17T11:00:45Z DEBUG SSHA512 2019-01-17T11:00:45Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG only: set nsslapd-sasl-mapping-fallback to 'on', current value [u'on'] 2019-01-17T11:00:45Z DEBUG only: updated value [u'on'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-betype: 2019-01-17T11:00:45Z DEBUG ldbm database 2019-01-17T11:00:45Z DEBUG nsslapd-nagle: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-referralmode: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:00:45Z DEBUG 64 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 500 2019-01-17T11:00:45Z DEBUG passwordMinAlphas: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-readonly: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordLegacyPolicy: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:00:45Z DEBUG allowed 2019-01-17T11:00:45Z DEBUG passwordMinUppers: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-plugin: 2019-01-17T11:00:45Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:00:45Z DEBUG 20971520 2019-01-17T11:00:45Z DEBUG nsslapd-timelimit: 2019-01-17T11:00:45Z DEBUG 3600 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinTokenLength: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordMinAge: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:00:45Z DEBUG 60 2019-01-17T11:00:45Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:00:45Z DEBUG 1024 2019-01-17T11:00:45Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordInHistory: 2019-01-17T11:00:45Z DEBUG 6 2019-01-17T11:00:45Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-conntablesize: 2019-01-17T11:00:45Z DEBUG 16384 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-saslpath: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG passwordMaxAge: 2019-01-17T11:00:45Z DEBUG 8640000 2019-01-17T11:00:45Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:00:45Z DEBUG gidNumber 2019-01-17T11:00:45Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG day 2019-01-17T11:00:45Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-csnlogging: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-tmpdir: 2019-01-17T11:00:45Z DEBUG /tmp 2019-01-17T11:00:45Z DEBUG passwordResetFailureCount: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-counters: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-svrtab: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-minssf: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-schemadir: 2019-01-17T11:00:45Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:00:45Z DEBUG nsslapd-localuser: 2019-01-17T11:00:45Z DEBUG dirsrv 2019-01-17T11:00:45Z DEBUG nsslapd-security: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordChange: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-port 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:00:45Z DEBUG passwordMaxFailure: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:00:45Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:00:45Z DEBUG 128 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:00:45Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-rootdn: 2019-01-17T11:00:45Z DEBUG cn=Directory Manager 2019-01-17T11:00:45Z DEBUG nsslapd-ldifdir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:00:45Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordMustChange: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordExp: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-logging-backend: 2019-01-17T11:00:45Z DEBUG dirsrv-log 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:45Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:00:45Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:00:45Z DEBUG cn=Directory Manager 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinLength: 2019-01-17T11:00:45Z DEBUG 8 2019-01-17T11:00:45Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-idletimeout: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-securePort: 2019-01-17T11:00:45Z DEBUG 636 2019-01-17T11:00:45Z DEBUG nsslapd-snmp-index: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG config 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapdConfig 2019-01-17T11:00:45Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordSendExpiringTime: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-hash-filters: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:00:45Z DEBUG next 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-listenhost: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordCheckSyntax: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordGraceLimit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG passwordWarning: 2019-01-17T11:00:45Z DEBUG 86400 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-instancedir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-config: 2019-01-17T11:00:45Z DEBUG cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-versionstring: 2019-01-17T11:00:45Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:00:45Z DEBUG 256 2019-01-17T11:00:45Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:00:45Z DEBUG SSHA512 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordLockout: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-lockdir: 2019-01-17T11:00:45Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-certdir: 2019-01-17T11:00:45Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 10 2019-01-17T11:00:45Z DEBUG nsslapd-backendconfig: 2019-01-17T11:00:45Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-threadnumber: 2019-01-17T11:00:45Z DEBUG 24 2019-01-17T11:00:45Z DEBUG nsslapd-schemamod: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-localhost: 2019-01-17T11:00:45Z DEBUG centos75.local 2019-01-17T11:00:45Z DEBUG nsslapd-bakdir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:00:45Z DEBUG passwordMin8bit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:00:45Z DEBUG uidNumber 2019-01-17T11:00:45Z DEBUG nsslapd-validate-cert: 2019-01-17T11:00:45Z DEBUG warn 2019-01-17T11:00:45Z DEBUG passwordMinCategories: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG passwordMinLowers: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordAdminDN: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordMinSpecials: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-lastmod: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:00:45Z DEBUG 40 2019-01-17T11:00:45Z DEBUG passwordMaxRepeats: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:00:45Z DEBUG -1 2019-01-17T11:00:45Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG nsslapd-result-tweak: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG passwordUnlock: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-schemacheck: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-maxbersize: 2019-01-17T11:00:45Z DEBUG 209715200 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:00:45Z DEBUG dc=example,dc=com 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-localssf: 2019-01-17T11:00:45Z DEBUG 71 2019-01-17T11:00:45Z DEBUG nsslapd-sizelimit: 2019-01-17T11:00:45Z DEBUG 2000 2019-01-17T11:00:45Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG passwordLockoutDuration: 2019-01-17T11:00:45Z DEBUG 3600 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-port: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:00:45Z DEBUG cn=schema 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG cn=monitor 2019-01-17T11:00:45Z DEBUG cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-rootpw: 2019-01-17T11:00:45Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:00:45Z DEBUG 300000 2019-01-17T11:00:45Z DEBUG nsslapd-workingdir: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-rundir: 2019-01-17T11:00:45Z DEBUG /var/run/dirsrv 2019-01-17T11:00:45Z DEBUG nsslapd-schemareplace: 2019-01-17T11:00:45Z DEBUG replication-only 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:00:45Z DEBUG 16384 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:00:45Z DEBUG 10000 2019-01-17T11:00:45Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinDigits: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG passwordStorageScheme: 2019-01-17T11:00:45Z DEBUG SSHA512 2019-01-17T11:00:45Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=Full Principal,cn=mapping,cn=sasl,cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=Full Principal,cn=mapping,cn=sasl,cn=config 2019-01-17T11:00:45Z DEBUG nsSaslMapPriority: 2019-01-17T11:00:45Z DEBUG 10 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG Full Principal 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSaslMapping 2019-01-17T11:00:45Z DEBUG nsSaslMapRegexString: 2019-01-17T11:00:45Z DEBUG \(.*\)@\(.*\) 2019-01-17T11:00:45Z DEBUG nsSaslMapBaseDNTemplate: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG nsSaslMapFilterTemplate: 2019-01-17T11:00:45Z DEBUG (krbPrincipalName=\1@\2) 2019-01-17T11:00:45Z DEBUG addifnew: '10' to nsSaslMapPriority, current value [u'10'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=Full Principal,cn=mapping,cn=sasl,cn=config 2019-01-17T11:00:45Z DEBUG nsSaslMapPriority: 2019-01-17T11:00:45Z DEBUG 10 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG Full Principal 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSaslMapping 2019-01-17T11:00:45Z DEBUG nsSaslMapRegexString: 2019-01-17T11:00:45Z DEBUG \(.*\)@\(.*\) 2019-01-17T11:00:45Z DEBUG nsSaslMapBaseDNTemplate: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG nsSaslMapFilterTemplate: 2019-01-17T11:00:45Z DEBUG (krbPrincipalName=\1@\2) 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=Name Only,cn=mapping,cn=sasl,cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=Name Only,cn=mapping,cn=sasl,cn=config 2019-01-17T11:00:45Z DEBUG nsSaslMapPriority: 2019-01-17T11:00:45Z DEBUG 10 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG Name Only 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSaslMapping 2019-01-17T11:00:45Z DEBUG nsSaslMapRegexString: 2019-01-17T11:00:45Z DEBUG ^[^:@]+$ 2019-01-17T11:00:45Z DEBUG nsSaslMapBaseDNTemplate: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG nsSaslMapFilterTemplate: 2019-01-17T11:00:45Z DEBUG (krbPrincipalName=&@LOCAL) 2019-01-17T11:00:45Z DEBUG addifnew: '10' to nsSaslMapPriority, current value [u'10'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=Name Only,cn=mapping,cn=sasl,cn=config 2019-01-17T11:00:45Z DEBUG nsSaslMapPriority: 2019-01-17T11:00:45Z DEBUG 10 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG Name Only 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSaslMapping 2019-01-17T11:00:45Z DEBUG nsSaslMapRegexString: 2019-01-17T11:00:45Z DEBUG ^[^:@]+$ 2019-01-17T11:00:45Z DEBUG nsSaslMapBaseDNTemplate: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG nsSaslMapFilterTemplate: 2019-01-17T11:00:45Z DEBUG (krbPrincipalName=&@LOCAL) 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-betype: 2019-01-17T11:00:45Z DEBUG ldbm database 2019-01-17T11:00:45Z DEBUG nsslapd-nagle: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-referralmode: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:00:45Z DEBUG 64 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 500 2019-01-17T11:00:45Z DEBUG passwordMinAlphas: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-readonly: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordLegacyPolicy: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:00:45Z DEBUG allowed 2019-01-17T11:00:45Z DEBUG passwordMinUppers: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-plugin: 2019-01-17T11:00:45Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:00:45Z DEBUG 20971520 2019-01-17T11:00:45Z DEBUG nsslapd-timelimit: 2019-01-17T11:00:45Z DEBUG 3600 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinTokenLength: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordMinAge: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:00:45Z DEBUG 60 2019-01-17T11:00:45Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:00:45Z DEBUG 1024 2019-01-17T11:00:45Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordInHistory: 2019-01-17T11:00:45Z DEBUG 6 2019-01-17T11:00:45Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-conntablesize: 2019-01-17T11:00:45Z DEBUG 16384 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-saslpath: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG passwordMaxAge: 2019-01-17T11:00:45Z DEBUG 8640000 2019-01-17T11:00:45Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:00:45Z DEBUG gidNumber 2019-01-17T11:00:45Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG day 2019-01-17T11:00:45Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-csnlogging: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-tmpdir: 2019-01-17T11:00:45Z DEBUG /tmp 2019-01-17T11:00:45Z DEBUG passwordResetFailureCount: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-counters: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-svrtab: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-minssf: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-schemadir: 2019-01-17T11:00:45Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:00:45Z DEBUG nsslapd-localuser: 2019-01-17T11:00:45Z DEBUG dirsrv 2019-01-17T11:00:45Z DEBUG nsslapd-security: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordChange: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-port 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:00:45Z DEBUG passwordMaxFailure: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:00:45Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:00:45Z DEBUG 128 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:00:45Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-rootdn: 2019-01-17T11:00:45Z DEBUG cn=Directory Manager 2019-01-17T11:00:45Z DEBUG nsslapd-ldifdir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:00:45Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordMustChange: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordExp: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-logging-backend: 2019-01-17T11:00:45Z DEBUG dirsrv-log 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:45Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:00:45Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:00:45Z DEBUG cn=Directory Manager 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinLength: 2019-01-17T11:00:45Z DEBUG 8 2019-01-17T11:00:45Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-idletimeout: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-securePort: 2019-01-17T11:00:45Z DEBUG 636 2019-01-17T11:00:45Z DEBUG nsslapd-snmp-index: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG config 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapdConfig 2019-01-17T11:00:45Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordSendExpiringTime: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-hash-filters: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:00:45Z DEBUG next 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-listenhost: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordCheckSyntax: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordGraceLimit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG passwordWarning: 2019-01-17T11:00:45Z DEBUG 86400 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-instancedir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-config: 2019-01-17T11:00:45Z DEBUG cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-versionstring: 2019-01-17T11:00:45Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:00:45Z DEBUG 256 2019-01-17T11:00:45Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:00:45Z DEBUG SSHA512 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordLockout: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-lockdir: 2019-01-17T11:00:45Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-certdir: 2019-01-17T11:00:45Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 10 2019-01-17T11:00:45Z DEBUG nsslapd-backendconfig: 2019-01-17T11:00:45Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-threadnumber: 2019-01-17T11:00:45Z DEBUG 24 2019-01-17T11:00:45Z DEBUG nsslapd-schemamod: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-localhost: 2019-01-17T11:00:45Z DEBUG centos75.local 2019-01-17T11:00:45Z DEBUG nsslapd-bakdir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:00:45Z DEBUG passwordMin8bit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:00:45Z DEBUG uidNumber 2019-01-17T11:00:45Z DEBUG nsslapd-validate-cert: 2019-01-17T11:00:45Z DEBUG warn 2019-01-17T11:00:45Z DEBUG passwordMinCategories: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG passwordMinLowers: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordAdminDN: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordMinSpecials: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-lastmod: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:00:45Z DEBUG 40 2019-01-17T11:00:45Z DEBUG passwordMaxRepeats: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:00:45Z DEBUG -1 2019-01-17T11:00:45Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG nsslapd-result-tweak: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG passwordUnlock: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-schemacheck: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-maxbersize: 2019-01-17T11:00:45Z DEBUG 209715200 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:00:45Z DEBUG dc=example,dc=com 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-localssf: 2019-01-17T11:00:45Z DEBUG 71 2019-01-17T11:00:45Z DEBUG nsslapd-sizelimit: 2019-01-17T11:00:45Z DEBUG 2000 2019-01-17T11:00:45Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG passwordLockoutDuration: 2019-01-17T11:00:45Z DEBUG 3600 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-port: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:00:45Z DEBUG cn=schema 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG cn=monitor 2019-01-17T11:00:45Z DEBUG cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-rootpw: 2019-01-17T11:00:45Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:00:45Z DEBUG 300000 2019-01-17T11:00:45Z DEBUG nsslapd-workingdir: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-rundir: 2019-01-17T11:00:45Z DEBUG /var/run/dirsrv 2019-01-17T11:00:45Z DEBUG nsslapd-schemareplace: 2019-01-17T11:00:45Z DEBUG replication-only 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:00:45Z DEBUG 16384 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:00:45Z DEBUG 10000 2019-01-17T11:00:45Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinDigits: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG passwordStorageScheme: 2019-01-17T11:00:45Z DEBUG SSHA512 2019-01-17T11:00:45Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG only: set nsslapd-allow-hashed-passwords to 'on', current value [u'on'] 2019-01-17T11:00:45Z DEBUG only: updated value [u'on'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-betype: 2019-01-17T11:00:45Z DEBUG ldbm database 2019-01-17T11:00:45Z DEBUG nsslapd-nagle: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-referralmode: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:00:45Z DEBUG 64 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 500 2019-01-17T11:00:45Z DEBUG passwordMinAlphas: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-readonly: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordLegacyPolicy: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:00:45Z DEBUG allowed 2019-01-17T11:00:45Z DEBUG passwordMinUppers: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-plugin: 2019-01-17T11:00:45Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:00:45Z DEBUG 20971520 2019-01-17T11:00:45Z DEBUG nsslapd-timelimit: 2019-01-17T11:00:45Z DEBUG 3600 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinTokenLength: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordMinAge: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:00:45Z DEBUG 60 2019-01-17T11:00:45Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:00:45Z DEBUG 1024 2019-01-17T11:00:45Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordInHistory: 2019-01-17T11:00:45Z DEBUG 6 2019-01-17T11:00:45Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-conntablesize: 2019-01-17T11:00:45Z DEBUG 16384 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-saslpath: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG passwordMaxAge: 2019-01-17T11:00:45Z DEBUG 8640000 2019-01-17T11:00:45Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:00:45Z DEBUG gidNumber 2019-01-17T11:00:45Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG day 2019-01-17T11:00:45Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-csnlogging: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-tmpdir: 2019-01-17T11:00:45Z DEBUG /tmp 2019-01-17T11:00:45Z DEBUG passwordResetFailureCount: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-counters: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-svrtab: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-minssf: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-schemadir: 2019-01-17T11:00:45Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:00:45Z DEBUG nsslapd-localuser: 2019-01-17T11:00:45Z DEBUG dirsrv 2019-01-17T11:00:45Z DEBUG nsslapd-security: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordChange: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-port 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:00:45Z DEBUG passwordMaxFailure: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:00:45Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:00:45Z DEBUG 128 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:00:45Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-rootdn: 2019-01-17T11:00:45Z DEBUG cn=Directory Manager 2019-01-17T11:00:45Z DEBUG nsslapd-ldifdir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:00:45Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordMustChange: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordExp: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-logging-backend: 2019-01-17T11:00:45Z DEBUG dirsrv-log 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:45Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:00:45Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:00:45Z DEBUG cn=Directory Manager 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinLength: 2019-01-17T11:00:45Z DEBUG 8 2019-01-17T11:00:45Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-idletimeout: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-securePort: 2019-01-17T11:00:45Z DEBUG 636 2019-01-17T11:00:45Z DEBUG nsslapd-snmp-index: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG config 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapdConfig 2019-01-17T11:00:45Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordSendExpiringTime: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-hash-filters: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:00:45Z DEBUG next 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-listenhost: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordCheckSyntax: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordGraceLimit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG passwordWarning: 2019-01-17T11:00:45Z DEBUG 86400 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-instancedir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-config: 2019-01-17T11:00:45Z DEBUG cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-versionstring: 2019-01-17T11:00:45Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:00:45Z DEBUG 256 2019-01-17T11:00:45Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:00:45Z DEBUG SSHA512 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordLockout: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-lockdir: 2019-01-17T11:00:45Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-certdir: 2019-01-17T11:00:45Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 10 2019-01-17T11:00:45Z DEBUG nsslapd-backendconfig: 2019-01-17T11:00:45Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-threadnumber: 2019-01-17T11:00:45Z DEBUG 24 2019-01-17T11:00:45Z DEBUG nsslapd-schemamod: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-localhost: 2019-01-17T11:00:45Z DEBUG centos75.local 2019-01-17T11:00:45Z DEBUG nsslapd-bakdir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:00:45Z DEBUG passwordMin8bit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:00:45Z DEBUG uidNumber 2019-01-17T11:00:45Z DEBUG nsslapd-validate-cert: 2019-01-17T11:00:45Z DEBUG warn 2019-01-17T11:00:45Z DEBUG passwordMinCategories: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG passwordMinLowers: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordAdminDN: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordMinSpecials: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-lastmod: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:00:45Z DEBUG 40 2019-01-17T11:00:45Z DEBUG passwordMaxRepeats: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:00:45Z DEBUG -1 2019-01-17T11:00:45Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG nsslapd-result-tweak: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG passwordUnlock: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-schemacheck: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-maxbersize: 2019-01-17T11:00:45Z DEBUG 209715200 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:00:45Z DEBUG dc=example,dc=com 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-localssf: 2019-01-17T11:00:45Z DEBUG 71 2019-01-17T11:00:45Z DEBUG nsslapd-sizelimit: 2019-01-17T11:00:45Z DEBUG 2000 2019-01-17T11:00:45Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG passwordLockoutDuration: 2019-01-17T11:00:45Z DEBUG 3600 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-port: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:00:45Z DEBUG cn=schema 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG cn=monitor 2019-01-17T11:00:45Z DEBUG cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-rootpw: 2019-01-17T11:00:45Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:00:45Z DEBUG 300000 2019-01-17T11:00:45Z DEBUG nsslapd-workingdir: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-rundir: 2019-01-17T11:00:45Z DEBUG /var/run/dirsrv 2019-01-17T11:00:45Z DEBUG nsslapd-schemareplace: 2019-01-17T11:00:45Z DEBUG replication-only 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:00:45Z DEBUG 16384 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:00:45Z DEBUG 10000 2019-01-17T11:00:45Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinDigits: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG passwordStorageScheme: 2019-01-17T11:00:45Z DEBUG SSHA512 2019-01-17T11:00:45Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-betype: 2019-01-17T11:00:45Z DEBUG ldbm database 2019-01-17T11:00:45Z DEBUG nsslapd-nagle: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-referralmode: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:00:45Z DEBUG 64 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 500 2019-01-17T11:00:45Z DEBUG passwordMinAlphas: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-readonly: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordLegacyPolicy: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:00:45Z DEBUG allowed 2019-01-17T11:00:45Z DEBUG passwordMinUppers: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-plugin: 2019-01-17T11:00:45Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:00:45Z DEBUG 20971520 2019-01-17T11:00:45Z DEBUG nsslapd-timelimit: 2019-01-17T11:00:45Z DEBUG 3600 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinTokenLength: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordMinAge: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:00:45Z DEBUG 60 2019-01-17T11:00:45Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:00:45Z DEBUG 1024 2019-01-17T11:00:45Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordInHistory: 2019-01-17T11:00:45Z DEBUG 6 2019-01-17T11:00:45Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-conntablesize: 2019-01-17T11:00:45Z DEBUG 16384 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-saslpath: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG passwordMaxAge: 2019-01-17T11:00:45Z DEBUG 8640000 2019-01-17T11:00:45Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:00:45Z DEBUG gidNumber 2019-01-17T11:00:45Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG day 2019-01-17T11:00:45Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-csnlogging: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-tmpdir: 2019-01-17T11:00:45Z DEBUG /tmp 2019-01-17T11:00:45Z DEBUG passwordResetFailureCount: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-counters: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-svrtab: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-minssf: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-schemadir: 2019-01-17T11:00:45Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:00:45Z DEBUG nsslapd-localuser: 2019-01-17T11:00:45Z DEBUG dirsrv 2019-01-17T11:00:45Z DEBUG nsslapd-security: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordChange: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-port 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:00:45Z DEBUG passwordMaxFailure: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:00:45Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:00:45Z DEBUG 128 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:00:45Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-rootdn: 2019-01-17T11:00:45Z DEBUG cn=Directory Manager 2019-01-17T11:00:45Z DEBUG nsslapd-ldifdir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:00:45Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordMustChange: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordExp: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-logging-backend: 2019-01-17T11:00:45Z DEBUG dirsrv-log 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:45Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:00:45Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:00:45Z DEBUG cn=Directory Manager 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinLength: 2019-01-17T11:00:45Z DEBUG 8 2019-01-17T11:00:45Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-idletimeout: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-securePort: 2019-01-17T11:00:45Z DEBUG 636 2019-01-17T11:00:45Z DEBUG nsslapd-snmp-index: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG config 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapdConfig 2019-01-17T11:00:45Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordSendExpiringTime: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-hash-filters: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:00:45Z DEBUG next 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-listenhost: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordCheckSyntax: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordGraceLimit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG passwordWarning: 2019-01-17T11:00:45Z DEBUG 86400 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-instancedir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-config: 2019-01-17T11:00:45Z DEBUG cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-versionstring: 2019-01-17T11:00:45Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:00:45Z DEBUG 256 2019-01-17T11:00:45Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:00:45Z DEBUG SSHA512 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordLockout: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-lockdir: 2019-01-17T11:00:45Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-certdir: 2019-01-17T11:00:45Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 10 2019-01-17T11:00:45Z DEBUG nsslapd-backendconfig: 2019-01-17T11:00:45Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-threadnumber: 2019-01-17T11:00:45Z DEBUG 24 2019-01-17T11:00:45Z DEBUG nsslapd-schemamod: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-localhost: 2019-01-17T11:00:45Z DEBUG centos75.local 2019-01-17T11:00:45Z DEBUG nsslapd-bakdir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:00:45Z DEBUG passwordMin8bit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:00:45Z DEBUG uidNumber 2019-01-17T11:00:45Z DEBUG nsslapd-validate-cert: 2019-01-17T11:00:45Z DEBUG warn 2019-01-17T11:00:45Z DEBUG passwordMinCategories: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG passwordMinLowers: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordAdminDN: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordMinSpecials: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-lastmod: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:00:45Z DEBUG 40 2019-01-17T11:00:45Z DEBUG passwordMaxRepeats: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:00:45Z DEBUG -1 2019-01-17T11:00:45Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG nsslapd-result-tweak: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG passwordUnlock: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-schemacheck: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-maxbersize: 2019-01-17T11:00:45Z DEBUG 209715200 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:00:45Z DEBUG dc=example,dc=com 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-localssf: 2019-01-17T11:00:45Z DEBUG 71 2019-01-17T11:00:45Z DEBUG nsslapd-sizelimit: 2019-01-17T11:00:45Z DEBUG 2000 2019-01-17T11:00:45Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG passwordLockoutDuration: 2019-01-17T11:00:45Z DEBUG 3600 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-port: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:00:45Z DEBUG cn=schema 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG cn=monitor 2019-01-17T11:00:45Z DEBUG cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-rootpw: 2019-01-17T11:00:45Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:00:45Z DEBUG 300000 2019-01-17T11:00:45Z DEBUG nsslapd-workingdir: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-rundir: 2019-01-17T11:00:45Z DEBUG /var/run/dirsrv 2019-01-17T11:00:45Z DEBUG nsslapd-schemareplace: 2019-01-17T11:00:45Z DEBUG replication-only 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:00:45Z DEBUG 16384 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:00:45Z DEBUG 10000 2019-01-17T11:00:45Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinDigits: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG passwordStorageScheme: 2019-01-17T11:00:45Z DEBUG SSHA512 2019-01-17T11:00:45Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG only: set nsslapd-ioblocktimeout to '10000', current value [u'10000'] 2019-01-17T11:00:45Z DEBUG only: updated value [u'10000'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-betype: 2019-01-17T11:00:45Z DEBUG ldbm database 2019-01-17T11:00:45Z DEBUG nsslapd-nagle: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-referralmode: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:00:45Z DEBUG 64 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 500 2019-01-17T11:00:45Z DEBUG passwordMinAlphas: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-readonly: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordLegacyPolicy: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:00:45Z DEBUG allowed 2019-01-17T11:00:45Z DEBUG passwordMinUppers: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-plugin: 2019-01-17T11:00:45Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:00:45Z DEBUG 20971520 2019-01-17T11:00:45Z DEBUG nsslapd-timelimit: 2019-01-17T11:00:45Z DEBUG 3600 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinTokenLength: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordMinAge: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:00:45Z DEBUG 60 2019-01-17T11:00:45Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:00:45Z DEBUG 1024 2019-01-17T11:00:45Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordInHistory: 2019-01-17T11:00:45Z DEBUG 6 2019-01-17T11:00:45Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-conntablesize: 2019-01-17T11:00:45Z DEBUG 16384 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-saslpath: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG passwordMaxAge: 2019-01-17T11:00:45Z DEBUG 8640000 2019-01-17T11:00:45Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:00:45Z DEBUG gidNumber 2019-01-17T11:00:45Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG day 2019-01-17T11:00:45Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-csnlogging: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-tmpdir: 2019-01-17T11:00:45Z DEBUG /tmp 2019-01-17T11:00:45Z DEBUG passwordResetFailureCount: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-counters: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-svrtab: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-minssf: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-schemadir: 2019-01-17T11:00:45Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:00:45Z DEBUG nsslapd-localuser: 2019-01-17T11:00:45Z DEBUG dirsrv 2019-01-17T11:00:45Z DEBUG nsslapd-security: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordChange: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-port 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:00:45Z DEBUG passwordMaxFailure: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:00:45Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:00:45Z DEBUG 128 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:00:45Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-rootdn: 2019-01-17T11:00:45Z DEBUG cn=Directory Manager 2019-01-17T11:00:45Z DEBUG nsslapd-ldifdir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:00:45Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordMustChange: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordExp: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-logging-backend: 2019-01-17T11:00:45Z DEBUG dirsrv-log 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:45Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:00:45Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:00:45Z DEBUG cn=Directory Manager 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinLength: 2019-01-17T11:00:45Z DEBUG 8 2019-01-17T11:00:45Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-idletimeout: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-securePort: 2019-01-17T11:00:45Z DEBUG 636 2019-01-17T11:00:45Z DEBUG nsslapd-snmp-index: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG config 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapdConfig 2019-01-17T11:00:45Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordSendExpiringTime: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-hash-filters: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:00:45Z DEBUG next 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-listenhost: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordCheckSyntax: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordGraceLimit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG passwordWarning: 2019-01-17T11:00:45Z DEBUG 86400 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-instancedir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-config: 2019-01-17T11:00:45Z DEBUG cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-versionstring: 2019-01-17T11:00:45Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:00:45Z DEBUG 256 2019-01-17T11:00:45Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:00:45Z DEBUG SSHA512 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordLockout: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-lockdir: 2019-01-17T11:00:45Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-certdir: 2019-01-17T11:00:45Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 10 2019-01-17T11:00:45Z DEBUG nsslapd-backendconfig: 2019-01-17T11:00:45Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-threadnumber: 2019-01-17T11:00:45Z DEBUG 24 2019-01-17T11:00:45Z DEBUG nsslapd-schemamod: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-localhost: 2019-01-17T11:00:45Z DEBUG centos75.local 2019-01-17T11:00:45Z DEBUG nsslapd-bakdir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:00:45Z DEBUG passwordMin8bit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:00:45Z DEBUG uidNumber 2019-01-17T11:00:45Z DEBUG nsslapd-validate-cert: 2019-01-17T11:00:45Z DEBUG warn 2019-01-17T11:00:45Z DEBUG passwordMinCategories: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG passwordMinLowers: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordAdminDN: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordMinSpecials: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-lastmod: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:00:45Z DEBUG 40 2019-01-17T11:00:45Z DEBUG passwordMaxRepeats: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:00:45Z DEBUG -1 2019-01-17T11:00:45Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG nsslapd-result-tweak: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG passwordUnlock: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-schemacheck: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-maxbersize: 2019-01-17T11:00:45Z DEBUG 209715200 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:00:45Z DEBUG dc=example,dc=com 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-localssf: 2019-01-17T11:00:45Z DEBUG 71 2019-01-17T11:00:45Z DEBUG nsslapd-sizelimit: 2019-01-17T11:00:45Z DEBUG 2000 2019-01-17T11:00:45Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG passwordLockoutDuration: 2019-01-17T11:00:45Z DEBUG 3600 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-port: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:00:45Z DEBUG cn=schema 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG cn=monitor 2019-01-17T11:00:45Z DEBUG cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-rootpw: 2019-01-17T11:00:45Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:00:45Z DEBUG 300000 2019-01-17T11:00:45Z DEBUG nsslapd-workingdir: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-rundir: 2019-01-17T11:00:45Z DEBUG /var/run/dirsrv 2019-01-17T11:00:45Z DEBUG nsslapd-schemareplace: 2019-01-17T11:00:45Z DEBUG replication-only 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:00:45Z DEBUG 16384 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:00:45Z DEBUG 10000 2019-01-17T11:00:45Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinDigits: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG passwordStorageScheme: 2019-01-17T11:00:45Z DEBUG SSHA512 2019-01-17T11:00:45Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Parsing update file '/usr/share/ipa/updates/10-enable-betxn.update' 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=7-bit check,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG NS7bitAttr 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG 7-bit check 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG NS7bitAttr_Init 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG Enforce 7-bit clean attribute values 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libattr-unique-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginarg0: 2019-01-17T11:00:45Z DEBUG uid 2019-01-17T11:00:45Z DEBUG nsslapd-pluginarg3: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-pluginarg2: 2019-01-17T11:00:45Z DEBUG , 2019-01-17T11:00:45Z DEBUG nsslapd-pluginarg1: 2019-01-17T11:00:45Z DEBUG mail 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG betxnpreoperation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value [u'betxnpreoperation'] 2019-01-17T11:00:45Z DEBUG only: updated value [u'betxnpreoperation'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG NS7bitAttr 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG 7-bit check 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG NS7bitAttr_Init 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG Enforce 7-bit clean attribute values 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libattr-unique-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginarg0: 2019-01-17T11:00:45Z DEBUG uid 2019-01-17T11:00:45Z DEBUG nsslapd-pluginarg3: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-pluginarg2: 2019-01-17T11:00:45Z DEBUG , 2019-01-17T11:00:45Z DEBUG nsslapd-pluginarg1: 2019-01-17T11:00:45Z DEBUG mail 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG betxnpreoperation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=attribute uniqueness,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=attribute uniqueness,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG uniqueness-attribute-name: 2019-01-17T11:00:45Z DEBUG uid 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG attribute uniqueness 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG uniqueness-across-all-subtrees: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libattr-unique-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG uniqueness-subtrees: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG betxnpreoperation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG NSUniqueAttr_Init 2019-01-17T11:00:45Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value [u'betxnpreoperation'] 2019-01-17T11:00:45Z DEBUG only: updated value [u'betxnpreoperation'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=attribute uniqueness,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG uniqueness-attribute-name: 2019-01-17T11:00:45Z DEBUG uid 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG attribute uniqueness 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG uniqueness-across-all-subtrees: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libattr-unique-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG uniqueness-subtrees: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG betxnpreoperation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG NSUniqueAttr_Init 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=Auto Membership Plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG Auto Membership 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG Auto Membership Plugin 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG Auto Membership plugin 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libautomember-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG nsslapd-pluginConfigArea: 2019-01-17T11:00:45Z DEBUG cn=automember,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG betxnpreoperation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG automember_init 2019-01-17T11:00:45Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value [u'betxnpreoperation'] 2019-01-17T11:00:45Z DEBUG only: updated value [u'betxnpreoperation'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG Auto Membership 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG Auto Membership Plugin 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG Auto Membership plugin 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libautomember-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG nsslapd-pluginConfigArea: 2019-01-17T11:00:45Z DEBUG cn=automember,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG betxnpreoperation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG automember_init 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=Linked Attributes,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=Linked Attributes,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG Linked Attributes 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG Linked Attributes 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG Linked Attributes plugin 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG liblinkedattrs-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsContainer 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG betxnpreoperation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG linked_attrs_init 2019-01-17T11:00:45Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value [u'betxnpreoperation'] 2019-01-17T11:00:45Z DEBUG only: updated value [u'betxnpreoperation'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=Linked Attributes,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG Linked Attributes 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG Linked Attributes 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG Linked Attributes plugin 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG liblinkedattrs-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsContainer 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG betxnpreoperation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG linked_attrs_init 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=Managed Entries,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG Managed Entries 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG Managed Entries 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG Managed Entries plugin 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libmanagedentries-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsContainer 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG nsslapd-pluginConfigArea: 2019-01-17T11:00:45Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG betxnpreoperation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG mep_init 2019-01-17T11:00:45Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value [u'betxnpreoperation'] 2019-01-17T11:00:45Z DEBUG only: updated value [u'betxnpreoperation'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG Managed Entries 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG Managed Entries 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG Managed Entries plugin 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libmanagedentries-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsContainer 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG nsslapd-pluginConfigArea: 2019-01-17T11:00:45Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG betxnpreoperation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG mep_init 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=MemberOf Plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=MemberOf Plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG memberof 2019-01-17T11:00:45Z DEBUG memberofgroupattr: 2019-01-17T11:00:45Z DEBUG member 2019-01-17T11:00:45Z DEBUG memberUser 2019-01-17T11:00:45Z DEBUG memberHost 2019-01-17T11:00:45Z DEBUG memberofentryscope: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG MemberOf Plugin 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG memberof plugin 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libmemberof-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG memberofattr: 2019-01-17T11:00:45Z DEBUG memberOf 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG betxnpostoperation 2019-01-17T11:00:45Z DEBUG memberofentryscopeexcludesubtree: 2019-01-17T11:00:45Z DEBUG cn=compat,dc=local 2019-01-17T11:00:45Z DEBUG cn=provisioning,dc=local 2019-01-17T11:00:45Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG memberof_postop_init 2019-01-17T11:00:45Z DEBUG only: set nsslapd-pluginType to 'betxnpostoperation', current value [u'betxnpostoperation'] 2019-01-17T11:00:45Z DEBUG only: updated value [u'betxnpostoperation'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=MemberOf Plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG memberof 2019-01-17T11:00:45Z DEBUG memberofgroupattr: 2019-01-17T11:00:45Z DEBUG member 2019-01-17T11:00:45Z DEBUG memberUser 2019-01-17T11:00:45Z DEBUG memberHost 2019-01-17T11:00:45Z DEBUG memberofentryscope: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG MemberOf Plugin 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG memberof plugin 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libmemberof-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG memberofattr: 2019-01-17T11:00:45Z DEBUG memberOf 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG betxnpostoperation 2019-01-17T11:00:45Z DEBUG memberofentryscopeexcludesubtree: 2019-01-17T11:00:45Z DEBUG cn=compat,dc=local 2019-01-17T11:00:45Z DEBUG cn=provisioning,dc=local 2019-01-17T11:00:45Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG memberof_postop_init 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=Multimaster Replication Plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=Multimaster Replication Plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG Multimaster Replication Plugin 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG replication_multimaster_plugin_init 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-named: 2019-01-17T11:00:45Z DEBUG ldbm database 2019-01-17T11:00:45Z DEBUG AES 2019-01-17T11:00:45Z DEBUG Class of Service 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG Multi-master Replication Plugin 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libreplication-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG replication-multimaster 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG object 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG only: set nsslapd-pluginbetxn to 'on', current value [u'on'] 2019-01-17T11:00:45Z DEBUG only: updated value [u'on'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=Multimaster Replication Plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG Multimaster Replication Plugin 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG replication_multimaster_plugin_init 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-named: 2019-01-17T11:00:45Z DEBUG ldbm database 2019-01-17T11:00:45Z DEBUG AES 2019-01-17T11:00:45Z DEBUG Class of Service 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG Multi-master Replication Plugin 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libreplication-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG replication-multimaster 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG object 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=PAM Pass Through Auth,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=PAM Pass Through Auth,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG pamFallback: 2019-01-17T11:00:45Z DEBUG FALSE 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG PAM Pass Through Auth 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG pamExcludeSuffix: 2019-01-17T11:00:45Z DEBUG cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG pamMissingSuffix: 2019-01-17T11:00:45Z DEBUG ALLOW 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libpam-passthru-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG pamConfig 2019-01-17T11:00:45Z DEBUG pamIDMapMethod: 2019-01-17T11:00:45Z DEBUG RDN 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG pamIDAttr: 2019-01-17T11:00:45Z DEBUG notUsedWithRDNMethod 2019-01-17T11:00:45Z DEBUG pamSecure: 2019-01-17T11:00:45Z DEBUG TRUE 2019-01-17T11:00:45Z DEBUG pamService: 2019-01-17T11:00:45Z DEBUG ldapserver 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG betxnpreoperation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginloadglobal: 2019-01-17T11:00:45Z DEBUG true 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG pam_passthruauth_init 2019-01-17T11:00:45Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value [u'betxnpreoperation'] 2019-01-17T11:00:45Z DEBUG only: updated value [u'betxnpreoperation'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=PAM Pass Through Auth,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG pamFallback: 2019-01-17T11:00:45Z DEBUG FALSE 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG PAM Pass Through Auth 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG pamExcludeSuffix: 2019-01-17T11:00:45Z DEBUG cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG pamMissingSuffix: 2019-01-17T11:00:45Z DEBUG ALLOW 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libpam-passthru-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG pamConfig 2019-01-17T11:00:45Z DEBUG pamIDMapMethod: 2019-01-17T11:00:45Z DEBUG RDN 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG pamIDAttr: 2019-01-17T11:00:45Z DEBUG notUsedWithRDNMethod 2019-01-17T11:00:45Z DEBUG pamSecure: 2019-01-17T11:00:45Z DEBUG TRUE 2019-01-17T11:00:45Z DEBUG pamService: 2019-01-17T11:00:45Z DEBUG ldapserver 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG betxnpreoperation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginloadglobal: 2019-01-17T11:00:45Z DEBUG true 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG pam_passthruauth_init 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=referential integrity postoperation,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG referint 2019-01-17T11:00:45Z DEBUG nsslapd-plugincontainerscope: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG referential integrity postoperation 2019-01-17T11:00:45Z DEBUG referint-update-delay: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-pluginexcludeentryscope: 2019-01-17T11:00:45Z DEBUG cn=provisioning,dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG referential integrity plugin 2019-01-17T11:00:45Z DEBUG nsslapd-pluginentryscope: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libreferint-plugin 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:00:45Z DEBUG 40 2019-01-17T11:00:45Z DEBUG referint-logfile: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/referint 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG betxnpostoperation 2019-01-17T11:00:45Z DEBUG referint-membership-attr: 2019-01-17T11:00:45Z DEBUG member 2019-01-17T11:00:45Z DEBUG uniquemember 2019-01-17T11:00:45Z DEBUG owner 2019-01-17T11:00:45Z DEBUG seeAlso 2019-01-17T11:00:45Z DEBUG manager 2019-01-17T11:00:45Z DEBUG secretary 2019-01-17T11:00:45Z DEBUG memberuser 2019-01-17T11:00:45Z DEBUG memberhost 2019-01-17T11:00:45Z DEBUG sourcehost 2019-01-17T11:00:45Z DEBUG memberservice 2019-01-17T11:00:45Z DEBUG managedby 2019-01-17T11:00:45Z DEBUG memberallowcmd 2019-01-17T11:00:45Z DEBUG memberdenycmd 2019-01-17T11:00:45Z DEBUG ipasudorunas 2019-01-17T11:00:45Z DEBUG ipasudorunasgroup 2019-01-17T11:00:45Z DEBUG ipatokenradiusconfiglink 2019-01-17T11:00:45Z DEBUG ipaassignedidview 2019-01-17T11:00:45Z DEBUG ipaallowedtarget 2019-01-17T11:00:45Z DEBUG ipamemberca 2019-01-17T11:00:45Z DEBUG ipamembercertprofile 2019-01-17T11:00:45Z DEBUG ipalocation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG referint_postop_init 2019-01-17T11:00:45Z DEBUG only: set nsslapd-pluginType to 'betxnpostoperation', current value [u'betxnpostoperation'] 2019-01-17T11:00:45Z DEBUG only: updated value [u'betxnpostoperation'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG referint 2019-01-17T11:00:45Z DEBUG nsslapd-plugincontainerscope: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG referential integrity postoperation 2019-01-17T11:00:45Z DEBUG referint-update-delay: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-pluginexcludeentryscope: 2019-01-17T11:00:45Z DEBUG cn=provisioning,dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG referential integrity plugin 2019-01-17T11:00:45Z DEBUG nsslapd-pluginentryscope: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libreferint-plugin 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:00:45Z DEBUG 40 2019-01-17T11:00:45Z DEBUG referint-logfile: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/referint 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG betxnpostoperation 2019-01-17T11:00:45Z DEBUG referint-membership-attr: 2019-01-17T11:00:45Z DEBUG member 2019-01-17T11:00:45Z DEBUG uniquemember 2019-01-17T11:00:45Z DEBUG owner 2019-01-17T11:00:45Z DEBUG seeAlso 2019-01-17T11:00:45Z DEBUG manager 2019-01-17T11:00:45Z DEBUG secretary 2019-01-17T11:00:45Z DEBUG memberuser 2019-01-17T11:00:45Z DEBUG memberhost 2019-01-17T11:00:45Z DEBUG sourcehost 2019-01-17T11:00:45Z DEBUG memberservice 2019-01-17T11:00:45Z DEBUG managedby 2019-01-17T11:00:45Z DEBUG memberallowcmd 2019-01-17T11:00:45Z DEBUG memberdenycmd 2019-01-17T11:00:45Z DEBUG ipasudorunas 2019-01-17T11:00:45Z DEBUG ipasudorunasgroup 2019-01-17T11:00:45Z DEBUG ipatokenradiusconfiglink 2019-01-17T11:00:45Z DEBUG ipaassignedidview 2019-01-17T11:00:45Z DEBUG ipaallowedtarget 2019-01-17T11:00:45Z DEBUG ipamemberca 2019-01-17T11:00:45Z DEBUG ipamembercertprofile 2019-01-17T11:00:45Z DEBUG ipalocation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG referint_postop_init 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=Roles Plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=Roles Plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG Roles Plugin 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-named: 2019-01-17T11:00:45Z DEBUG State Change Plugin 2019-01-17T11:00:45Z DEBUG Views 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG roles plugin 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libroles-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG roles 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG roles_init 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG object 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG only: set nsslapd-pluginbetxn to 'on', current value [u'on'] 2019-01-17T11:00:45Z DEBUG only: updated value [u'on'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=Roles Plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG Roles Plugin 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-named: 2019-01-17T11:00:45Z DEBUG State Change Plugin 2019-01-17T11:00:45Z DEBUG Views 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG roles plugin 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libroles-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG roles 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG roles_init 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG object 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=State Change Plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=State Change Plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG statechange 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG State Change Plugin 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG state change notification service plugin 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libstatechange-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG betxnpostoperation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG statechange_init 2019-01-17T11:00:45Z DEBUG only: set nsslapd-pluginType to 'betxnpostoperation', current value [u'betxnpostoperation'] 2019-01-17T11:00:45Z DEBUG only: updated value [u'betxnpostoperation'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=State Change Plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG statechange 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG State Change Plugin 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG state change notification service plugin 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libstatechange-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG betxnpostoperation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG statechange_init 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=USN,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=USN,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG USN 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG USN (Update Sequence Number) plugin 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libusn-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG USN 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG usn_init 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG object 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG only: set nsslapd-pluginbetxn to 'on', current value [u'on'] 2019-01-17T11:00:45Z DEBUG only: updated value [u'on'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=USN,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG USN 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG USN (Update Sequence Number) plugin 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libusn-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG USN 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG usn_init 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG object 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=IPA MODRDN,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=IPA MODRDN,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG IPA MODRDN 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG IPA MODRDN 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.0 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG IPA MODRDN plugin 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libipa_modrdn 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG Red Hat, Inc. 2019-01-17T11:00:45Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:00:45Z DEBUG 60 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG betxnpostoperation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG ipamodrdn_init 2019-01-17T11:00:45Z DEBUG only: set nsslapd-plugintype to 'betxnpostoperation', current value [u'betxnpostoperation'] 2019-01-17T11:00:45Z DEBUG only: updated value [u'betxnpostoperation'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=IPA MODRDN,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG IPA MODRDN 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG IPA MODRDN 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.0 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG IPA MODRDN plugin 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libipa_modrdn 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG Red Hat, Inc. 2019-01-17T11:00:45Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:00:45Z DEBUG 60 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG betxnpostoperation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG ipamodrdn_init 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=ipa_pwd_extop,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=ipa_pwd_extop,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG ipa_pwd_extop 2019-01-17T11:00:45Z DEBUG nsslapd-realmtree: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG FreeIPA/1.0 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG IPA Password Extended Operation plugin 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libipa_pwd_extop 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG IPA Password Manager 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG ipapwd_init 2019-01-17T11:00:45Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:00:45Z DEBUG 49 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG extendedop 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG FreeIPA project 2019-01-17T11:00:45Z DEBUG only: set nsslapd-pluginbetxn to 'on', current value [u'on'] 2019-01-17T11:00:45Z DEBUG only: updated value [u'on'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=ipa_pwd_extop,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG ipa_pwd_extop 2019-01-17T11:00:45Z DEBUG nsslapd-realmtree: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG FreeIPA/1.0 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG IPA Password Extended Operation plugin 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libipa_pwd_extop 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG IPA Password Manager 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG ipapwd_init 2019-01-17T11:00:45Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:00:45Z DEBUG 49 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG extendedop 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG FreeIPA project 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG Schema Compatibility 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG /usr/lib64/dirsrv/plugins/schemacompat-plugin.so 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG schema_compat_plugin_init 2019-01-17T11:00:45Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:00:45Z DEBUG 40 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG object 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG onlyifexist: 'on' to nsslapd-pluginbetxn, current value [u'on'] 2019-01-17T11:00:45Z DEBUG onlyifexist: set nsslapd-pluginbetxn to [u'on'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG Schema Compatibility 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG /usr/lib64/dirsrv/plugins/schemacompat-plugin.so 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG schema_compat_plugin_init 2019-01-17T11:00:45Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:00:45Z DEBUG 40 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG object 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG New entry: cn=NIS Server,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=NIS Server,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG onlyifexist: 'on' to nsslapd-pluginbetxn, current value [] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=NIS Server,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG Parsing update file '/usr/share/ipa/updates/10-ipapwd.update' 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=ipa_pwd_extop,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=ipa_pwd_extop,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG ipa_pwd_extop 2019-01-17T11:00:45Z DEBUG nsslapd-realmtree: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG FreeIPA/1.0 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG IPA Password Extended Operation plugin 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libipa_pwd_extop 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG IPA Password Manager 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG ipapwd_init 2019-01-17T11:00:45Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:00:45Z DEBUG 49 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG extendedop 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG FreeIPA project 2019-01-17T11:00:45Z DEBUG add: '49' to nsslapd-pluginprecedence, current value [u'49'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'49'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=ipa_pwd_extop,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG ipa_pwd_extop 2019-01-17T11:00:45Z DEBUG nsslapd-realmtree: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG FreeIPA/1.0 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG IPA Password Extended Operation plugin 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libipa_pwd_extop 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG IPA Password Manager 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG ipapwd_init 2019-01-17T11:00:45Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:00:45Z DEBUG 49 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG extendedop 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG FreeIPA project 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Parsing update file '/usr/share/ipa/updates/10-rootdse.update' 2019-01-17T11:00:45Z DEBUG Updating existing entry: 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: 2019-01-17T11:00:45Z DEBUG netscapemdsuffix: 2019-01-17T11:00:45Z DEBUG cn=ldap://dc=centos75,dc=local:0 2019-01-17T11:00:45Z DEBUG supportedLDAPVersion: 2019-01-17T11:00:45Z DEBUG 2 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG ipaDomainLevel: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetattr != "aci")(version 3.0; aci "rootdse anon read access"; allow(read,search,compare) userdn="ldap:///anyone";) 2019-01-17T11:00:45Z DEBUG dataversion: 2019-01-17T11:00:45Z DEBUG 020190117110040020190117110040020190117110040 2019-01-17T11:00:45Z DEBUG lastusn: 2019-01-17T11:00:45Z DEBUG 426 2019-01-17T11:00:45Z DEBUG vendorName: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG supportedSASLMechanisms: 2019-01-17T11:00:45Z DEBUG EXTERNAL 2019-01-17T11:00:45Z DEBUG SCRAM-SHA-1 2019-01-17T11:00:45Z DEBUG GSS-SPNEGO 2019-01-17T11:00:45Z DEBUG GSSAPI 2019-01-17T11:00:45Z DEBUG DIGEST-MD5 2019-01-17T11:00:45Z DEBUG CRAM-MD5 2019-01-17T11:00:45Z DEBUG LOGIN 2019-01-17T11:00:45Z DEBUG PLAIN 2019-01-17T11:00:45Z DEBUG ANONYMOUS 2019-01-17T11:00:45Z DEBUG lastchangenumber: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG defaultnamingcontext: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG ipatopologyismanaged: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG supportedExtension: 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.5.7 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.5.8 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.5.10 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.8.10.3 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.8.10.4 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.8.10.4.1 2019-01-17T11:00:45Z DEBUG 1.3.6.1.4.1.4203.1.11.1 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.8.10.1 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.8.10.5 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.5.3 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.5.12 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.5.5 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.5.6 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.5.9 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.5.4 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.6.5 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.6.6 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.6.7 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.6.8 2019-01-17T11:00:45Z DEBUG 1.3.6.1.4.1.4203.1.11.3 2019-01-17T11:00:45Z DEBUG supportedControl: 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.4.2 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.4.3 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.4.4 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.4.5 2019-01-17T11:00:45Z DEBUG 1.2.840.113556.1.4.473 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.4.9 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.4.16 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.4.15 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.4.17 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.4.19 2019-01-17T11:00:45Z DEBUG 1.3.6.1.1.13.1 2019-01-17T11:00:45Z DEBUG 1.3.6.1.1.13.2 2019-01-17T11:00:45Z DEBUG 1.3.6.1.4.1.42.2.27.8.5.1 2019-01-17T11:00:45Z DEBUG 1.3.6.1.4.1.42.2.27.9.5.2 2019-01-17T11:00:45Z DEBUG 1.2.840.113556.1.4.319 2019-01-17T11:00:45Z DEBUG 1.3.6.1.4.1.42.2.27.9.5.8 2019-01-17T11:00:45Z DEBUG 1.3.6.1.4.1.4203.666.5.16 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.8.10.6 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.8.10.7 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.4.14 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.4.20 2019-01-17T11:00:45Z DEBUG 1.3.6.1.4.1.1466.29539.12 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.4.12 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.4.18 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.4.13 2019-01-17T11:00:45Z DEBUG 1.3.6.1.4.1.4203.1.9.1.1 2019-01-17T11:00:45Z DEBUG changeLog: 2019-01-17T11:00:45Z DEBUG cn=changelog 2019-01-17T11:00:45Z DEBUG ipatopologypluginversion: 2019-01-17T11:00:45Z DEBUG 1.0 2019-01-17T11:00:45Z DEBUG firstchangenumber: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG namingContexts: 2019-01-17T11:00:45Z DEBUG cn=changelog 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG o=ipaca 2019-01-17T11:00:45Z DEBUG vendorVersion: 2019-01-17T11:00:45Z DEBUG 389-Directory/1.3.8.4 B2018.332.2046 2019-01-17T11:00:45Z DEBUG add: 'namingContexts' to nsslapd-return-default-opattr, current value [] 2019-01-17T11:00:45Z DEBUG add: updated value [u'namingContexts'] 2019-01-17T11:00:45Z DEBUG add: 'supportedControl' to nsslapd-return-default-opattr, current value [u'namingContexts'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'namingContexts', u'supportedControl'] 2019-01-17T11:00:45Z DEBUG add: 'supportedExtension' to nsslapd-return-default-opattr, current value [u'namingContexts', u'supportedControl'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'namingContexts', u'supportedControl', u'supportedExtension'] 2019-01-17T11:00:45Z DEBUG add: 'supportedLDAPVersion' to nsslapd-return-default-opattr, current value [u'namingContexts', u'supportedControl', u'supportedExtension'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'namingContexts', u'supportedControl', u'supportedExtension', u'supportedLDAPVersion'] 2019-01-17T11:00:45Z DEBUG add: 'supportedSASLMechanisms' to nsslapd-return-default-opattr, current value [u'namingContexts', u'supportedControl', u'supportedExtension', u'supportedLDAPVersion'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'namingContexts', u'supportedControl', u'supportedExtension', u'supportedLDAPVersion', u'supportedSASLMechanisms'] 2019-01-17T11:00:45Z DEBUG add: 'vendorName' to nsslapd-return-default-opattr, current value [u'namingContexts', u'supportedControl', u'supportedExtension', u'supportedLDAPVersion', u'supportedSASLMechanisms'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'namingContexts', u'supportedControl', u'supportedExtension', u'supportedLDAPVersion', u'supportedSASLMechanisms', u'vendorName'] 2019-01-17T11:00:45Z DEBUG add: 'vendorVersion' to nsslapd-return-default-opattr, current value [u'namingContexts', u'supportedControl', u'supportedExtension', u'supportedLDAPVersion', u'supportedSASLMechanisms', u'vendorName'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'namingContexts', u'supportedControl', u'supportedExtension', u'supportedLDAPVersion', u'supportedSASLMechanisms', u'vendorName', u'vendorVersion'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: 2019-01-17T11:00:45Z DEBUG netscapemdsuffix: 2019-01-17T11:00:45Z DEBUG cn=ldap://dc=centos75,dc=local:0 2019-01-17T11:00:45Z DEBUG supportedLDAPVersion: 2019-01-17T11:00:45Z DEBUG 2 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG ipaDomainLevel: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetattr != "aci")(version 3.0; aci "rootdse anon read access"; allow(read,search,compare) userdn="ldap:///anyone";) 2019-01-17T11:00:45Z DEBUG dataversion: 2019-01-17T11:00:45Z DEBUG 020190117110040020190117110040020190117110040 2019-01-17T11:00:45Z DEBUG lastusn: 2019-01-17T11:00:45Z DEBUG 426 2019-01-17T11:00:45Z DEBUG vendorName: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG supportedSASLMechanisms: 2019-01-17T11:00:45Z DEBUG EXTERNAL 2019-01-17T11:00:45Z DEBUG SCRAM-SHA-1 2019-01-17T11:00:45Z DEBUG GSS-SPNEGO 2019-01-17T11:00:45Z DEBUG GSSAPI 2019-01-17T11:00:45Z DEBUG DIGEST-MD5 2019-01-17T11:00:45Z DEBUG CRAM-MD5 2019-01-17T11:00:45Z DEBUG LOGIN 2019-01-17T11:00:45Z DEBUG PLAIN 2019-01-17T11:00:45Z DEBUG ANONYMOUS 2019-01-17T11:00:45Z DEBUG lastchangenumber: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG defaultnamingcontext: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG ipatopologyismanaged: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG supportedExtension: 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.5.7 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.5.8 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.5.10 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.8.10.3 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.8.10.4 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.8.10.4.1 2019-01-17T11:00:45Z DEBUG 1.3.6.1.4.1.4203.1.11.1 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.8.10.1 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.8.10.5 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.5.3 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.5.12 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.5.5 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.5.6 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.5.9 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.5.4 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.6.5 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.6.6 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.6.7 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.6.8 2019-01-17T11:00:45Z DEBUG 1.3.6.1.4.1.4203.1.11.3 2019-01-17T11:00:45Z DEBUG nsslapd-return-default-opattr: 2019-01-17T11:00:45Z DEBUG namingContexts 2019-01-17T11:00:45Z DEBUG supportedControl 2019-01-17T11:00:45Z DEBUG supportedExtension 2019-01-17T11:00:45Z DEBUG supportedLDAPVersion 2019-01-17T11:00:45Z DEBUG supportedSASLMechanisms 2019-01-17T11:00:45Z DEBUG vendorName 2019-01-17T11:00:45Z DEBUG vendorVersion 2019-01-17T11:00:45Z DEBUG supportedControl: 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.4.2 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.4.3 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.4.4 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.4.5 2019-01-17T11:00:45Z DEBUG 1.2.840.113556.1.4.473 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.4.9 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.4.16 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.4.15 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.4.17 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.4.19 2019-01-17T11:00:45Z DEBUG 1.3.6.1.1.13.1 2019-01-17T11:00:45Z DEBUG 1.3.6.1.1.13.2 2019-01-17T11:00:45Z DEBUG 1.3.6.1.4.1.42.2.27.8.5.1 2019-01-17T11:00:45Z DEBUG 1.3.6.1.4.1.42.2.27.9.5.2 2019-01-17T11:00:45Z DEBUG 1.2.840.113556.1.4.319 2019-01-17T11:00:45Z DEBUG 1.3.6.1.4.1.42.2.27.9.5.8 2019-01-17T11:00:45Z DEBUG 1.3.6.1.4.1.4203.666.5.16 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.8.10.6 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.8.10.7 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.4.14 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.4.20 2019-01-17T11:00:45Z DEBUG 1.3.6.1.4.1.1466.29539.12 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.4.12 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.4.18 2019-01-17T11:00:45Z DEBUG 2.16.840.1.113730.3.4.13 2019-01-17T11:00:45Z DEBUG 1.3.6.1.4.1.4203.1.9.1.1 2019-01-17T11:00:45Z DEBUG changeLog: 2019-01-17T11:00:45Z DEBUG cn=changelog 2019-01-17T11:00:45Z DEBUG ipatopologypluginversion: 2019-01-17T11:00:45Z DEBUG 1.0 2019-01-17T11:00:45Z DEBUG firstchangenumber: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG namingContexts: 2019-01-17T11:00:45Z DEBUG cn=changelog 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG o=ipaca 2019-01-17T11:00:45Z DEBUG vendorVersion: 2019-01-17T11:00:45Z DEBUG 389-Directory/1.3.8.4 B2018.332.2046 2019-01-17T11:00:45Z DEBUG [(2, u'nsslapd-return-default-opattr', [u'namingContexts', u'supportedControl', u'supportedExtension', u'supportedLDAPVersion', u'supportedSASLMechanisms', u'vendorName', u'vendorVersion'])] 2019-01-17T11:00:45Z DEBUG Updated 1 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Parsing update file '/usr/share/ipa/updates/10-selinuxusermap.update' 2019-01-17T11:00:45Z DEBUG New entry: cn=selinux,dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=selinux,dc=local 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsContainer 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG selinux 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=selinux,dc=local 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsContainer 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG selinux 2019-01-17T11:00:45Z DEBUG Unhandled LDAPError: OPERATIONS_ERROR: {'desc': 'Operations error'} 2019-01-17T11:00:45Z ERROR Add failure Operations error: 2019-01-17T11:00:45Z DEBUG New entry: cn=usermap,cn=selinux,dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=usermap,cn=selinux,dc=local 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsContainer 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG usermap 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=usermap,cn=selinux,dc=local 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsContainer 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG usermap 2019-01-17T11:00:45Z ERROR Parent DN of cn=usermap,cn=selinux,dc=local may not exist, cannot create the entry 2019-01-17T11:00:45Z DEBUG Parsing update file '/usr/share/ipa/updates/10-uniqueness.update' 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=sudorule name uniqueness,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=sudorule name uniqueness,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG uniqueness-attribute-name: 2019-01-17T11:00:45Z DEBUG cn 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG NSUniqueAttr 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG sudorule name uniqueness 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG Enforce unique attribute values 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libattr-unique-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG uniqueness-subtrees: 2019-01-17T11:00:45Z DEBUG cn=sudorules,cn=sudo,dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG preoperation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG NSUniqueAttr_Init 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=sudorule name uniqueness,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG uniqueness-attribute-name: 2019-01-17T11:00:45Z DEBUG cn 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG NSUniqueAttr 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG sudorule name uniqueness 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG Enforce unique attribute values 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libattr-unique-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG uniqueness-subtrees: 2019-01-17T11:00:45Z DEBUG cn=sudorules,cn=sudo,dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG preoperation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG NSUniqueAttr_Init 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=certificate store subject uniqueness,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=certificate store subject uniqueness,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG uniqueness-attribute-name: 2019-01-17T11:00:45Z DEBUG ipaCertSubject 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG NSUniqueAttr 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG certificate store subject uniqueness 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG Enforce unique attribute values 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libattr-unique-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG uniqueness-subtrees: 2019-01-17T11:00:45Z DEBUG cn=certificates,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG preoperation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG NSUniqueAttr_Init 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=certificate store subject uniqueness,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG uniqueness-attribute-name: 2019-01-17T11:00:45Z DEBUG ipaCertSubject 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG NSUniqueAttr 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG certificate store subject uniqueness 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG Enforce unique attribute values 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libattr-unique-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG uniqueness-subtrees: 2019-01-17T11:00:45Z DEBUG cn=certificates,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG preoperation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG NSUniqueAttr_Init 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=certificate store issuer/serial uniqueness,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=certificate store issuer/serial uniqueness,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG uniqueness-attribute-name: 2019-01-17T11:00:45Z DEBUG ipaCertIssuerSerial 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG NSUniqueAttr 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG certificate store issuer/serial uniqueness 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG Enforce unique attribute values 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libattr-unique-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG uniqueness-subtrees: 2019-01-17T11:00:45Z DEBUG cn=certificates,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG preoperation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG NSUniqueAttr_Init 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=certificate store issuer/serial uniqueness,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG uniqueness-attribute-name: 2019-01-17T11:00:45Z DEBUG ipaCertIssuerSerial 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG NSUniqueAttr 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG certificate store issuer/serial uniqueness 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG Enforce unique attribute values 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libattr-unique-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG uniqueness-subtrees: 2019-01-17T11:00:45Z DEBUG cn=certificates,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG preoperation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG NSUniqueAttr_Init 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=uid uniqueness,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=uid uniqueness,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG uniqueness-attribute-name: 2019-01-17T11:00:45Z DEBUG uid 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG NSUniqueAttr 2019-01-17T11:00:45Z DEBUG uniqueness-subtree-entries-oc: 2019-01-17T11:00:45Z DEBUG posixAccount 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG uid uniqueness 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG Enforce unique attribute values 2019-01-17T11:00:45Z DEBUG uniqueness-across-all-subtrees: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libattr-unique-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG uniqueness-exclude-subtrees: 2019-01-17T11:00:45Z DEBUG cn=compat,dc=local 2019-01-17T11:00:45Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:00:45Z DEBUG uniqueness-subtrees: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG preoperation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG NSUniqueAttr_Init 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=uid uniqueness,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG uniqueness-attribute-name: 2019-01-17T11:00:45Z DEBUG uid 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG NSUniqueAttr 2019-01-17T11:00:45Z DEBUG uniqueness-subtree-entries-oc: 2019-01-17T11:00:45Z DEBUG posixAccount 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG uid uniqueness 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG Enforce unique attribute values 2019-01-17T11:00:45Z DEBUG uniqueness-across-all-subtrees: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libattr-unique-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG uniqueness-exclude-subtrees: 2019-01-17T11:00:45Z DEBUG cn=compat,dc=local 2019-01-17T11:00:45Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:00:45Z DEBUG uniqueness-subtrees: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG preoperation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG NSUniqueAttr_Init 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=uid uniqueness,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=uid uniqueness,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG uniqueness-attribute-name: 2019-01-17T11:00:45Z DEBUG uid 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG NSUniqueAttr 2019-01-17T11:00:45Z DEBUG uniqueness-subtree-entries-oc: 2019-01-17T11:00:45Z DEBUG posixAccount 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG uid uniqueness 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG Enforce unique attribute values 2019-01-17T11:00:45Z DEBUG uniqueness-across-all-subtrees: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libattr-unique-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG uniqueness-exclude-subtrees: 2019-01-17T11:00:45Z DEBUG cn=compat,dc=local 2019-01-17T11:00:45Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:00:45Z DEBUG uniqueness-subtrees: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG preoperation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG NSUniqueAttr_Init 2019-01-17T11:00:45Z DEBUG add: 'cn=compat,dc=local' to uniqueness-exclude-subtrees, current value [u'cn=compat,dc=local', u'cn=staged users,cn=accounts,cn=provisioning,dc=local'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'cn=staged users,cn=accounts,cn=provisioning,dc=local', u'cn=compat,dc=local'] 2019-01-17T11:00:45Z DEBUG add: 'cn=staged users,cn=accounts,cn=provisioning,dc=local' to uniqueness-exclude-subtrees, current value [u'cn=staged users,cn=accounts,cn=provisioning,dc=local', u'cn=compat,dc=local'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'cn=compat,dc=local', u'cn=staged users,cn=accounts,cn=provisioning,dc=local'] 2019-01-17T11:00:45Z DEBUG remove: 'off' from uniqueness-across-all-subtrees, current value [u'on'] 2019-01-17T11:00:45Z DEBUG remove: 'off' not in uniqueness-across-all-subtrees 2019-01-17T11:00:45Z DEBUG add: 'on' to uniqueness-across-all-subtrees, current value [u'on'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'on'] 2019-01-17T11:00:45Z DEBUG add: 'posixAccount' to uniqueness-subtree-entries-oc, current value [u'posixAccount'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'posixAccount'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=uid uniqueness,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG uniqueness-attribute-name: 2019-01-17T11:00:45Z DEBUG uid 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG NSUniqueAttr 2019-01-17T11:00:45Z DEBUG uniqueness-subtree-entries-oc: 2019-01-17T11:00:45Z DEBUG posixAccount 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG uid uniqueness 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG Enforce unique attribute values 2019-01-17T11:00:45Z DEBUG uniqueness-across-all-subtrees: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libattr-unique-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG uniqueness-exclude-subtrees: 2019-01-17T11:00:45Z DEBUG cn=compat,dc=local 2019-01-17T11:00:45Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:00:45Z DEBUG uniqueness-subtrees: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG preoperation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG NSUniqueAttr_Init 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=krbPrincipalName uniqueness,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=krbPrincipalName uniqueness,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG uniqueness-attribute-name: 2019-01-17T11:00:45Z DEBUG krbPrincipalName 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG NSUniqueAttr 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG krbPrincipalName uniqueness 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG Enforce unique attribute values 2019-01-17T11:00:45Z DEBUG uniqueness-across-all-subtrees: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libattr-unique-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG uniqueness-exclude-subtrees: 2019-01-17T11:00:45Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:00:45Z DEBUG uniqueness-subtrees: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG preoperation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG NSUniqueAttr_Init 2019-01-17T11:00:45Z DEBUG add: 'cn=staged users,cn=accounts,cn=provisioning,dc=local' to uniqueness-exclude-subtrees, current value [u'cn=staged users,cn=accounts,cn=provisioning,dc=local'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'cn=staged users,cn=accounts,cn=provisioning,dc=local'] 2019-01-17T11:00:45Z DEBUG add: 'on' to uniqueness-across-all-subtrees, current value [u'on'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'on'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=krbPrincipalName uniqueness,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG uniqueness-attribute-name: 2019-01-17T11:00:45Z DEBUG krbPrincipalName 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG NSUniqueAttr 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG krbPrincipalName uniqueness 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG Enforce unique attribute values 2019-01-17T11:00:45Z DEBUG uniqueness-across-all-subtrees: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libattr-unique-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG uniqueness-exclude-subtrees: 2019-01-17T11:00:45Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:00:45Z DEBUG uniqueness-subtrees: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG preoperation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG NSUniqueAttr_Init 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=krbCanonicalName uniqueness,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=krbCanonicalName uniqueness,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG uniqueness-attribute-name: 2019-01-17T11:00:45Z DEBUG krbCanonicalName 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG NSUniqueAttr 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG krbCanonicalName uniqueness 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG Enforce unique attribute values 2019-01-17T11:00:45Z DEBUG uniqueness-across-all-subtrees: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libattr-unique-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG uniqueness-exclude-subtrees: 2019-01-17T11:00:45Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:00:45Z DEBUG uniqueness-subtrees: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG preoperation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG NSUniqueAttr_Init 2019-01-17T11:00:45Z DEBUG add: 'cn=staged users,cn=accounts,cn=provisioning,dc=local' to uniqueness-exclude-subtrees, current value [u'cn=staged users,cn=accounts,cn=provisioning,dc=local'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'cn=staged users,cn=accounts,cn=provisioning,dc=local'] 2019-01-17T11:00:45Z DEBUG add: 'on' to uniqueness-across-all-subtrees, current value [u'on'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'on'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=krbCanonicalName uniqueness,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG uniqueness-attribute-name: 2019-01-17T11:00:45Z DEBUG krbCanonicalName 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG NSUniqueAttr 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG krbCanonicalName uniqueness 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG Enforce unique attribute values 2019-01-17T11:00:45Z DEBUG uniqueness-across-all-subtrees: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libattr-unique-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG uniqueness-exclude-subtrees: 2019-01-17T11:00:45Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:00:45Z DEBUG uniqueness-subtrees: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG preoperation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG NSUniqueAttr_Init 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=ipaUniqueID uniqueness,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=ipaUniqueID uniqueness,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG uniqueness-attribute-name: 2019-01-17T11:00:45Z DEBUG ipaUniqueID 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG NSUniqueAttr 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG ipaUniqueID uniqueness 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG Enforce unique attribute values 2019-01-17T11:00:45Z DEBUG uniqueness-across-all-subtrees: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libattr-unique-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG uniqueness-exclude-subtrees: 2019-01-17T11:00:45Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:00:45Z DEBUG uniqueness-subtrees: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG preoperation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG NSUniqueAttr_Init 2019-01-17T11:00:45Z DEBUG add: 'cn=staged users,cn=accounts,cn=provisioning,dc=local' to uniqueness-exclude-subtrees, current value [u'cn=staged users,cn=accounts,cn=provisioning,dc=local'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'cn=staged users,cn=accounts,cn=provisioning,dc=local'] 2019-01-17T11:00:45Z DEBUG add: 'on' to uniqueness-across-all-subtrees, current value [u'on'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'on'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=ipaUniqueID uniqueness,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG uniqueness-attribute-name: 2019-01-17T11:00:45Z DEBUG ipaUniqueID 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG NSUniqueAttr 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG ipaUniqueID uniqueness 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG Enforce unique attribute values 2019-01-17T11:00:45Z DEBUG uniqueness-across-all-subtrees: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libattr-unique-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG uniqueness-exclude-subtrees: 2019-01-17T11:00:45Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:00:45Z DEBUG uniqueness-subtrees: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG preoperation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG NSUniqueAttr_Init 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Parsing update file '/usr/share/ipa/updates/19-managed-entries.update' 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=Managed Entries,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG Managed Entries 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG Managed Entries 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG Managed Entries plugin 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libmanagedentries-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsContainer 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG nsslapd-pluginConfigArea: 2019-01-17T11:00:45Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG betxnpreoperation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG mep_init 2019-01-17T11:00:45Z DEBUG only: set nsslapd-pluginConfigArea to 'cn=Definitions,cn=Managed Entries,cn=etc,dc=local', current value [u'cn=Definitions,cn=Managed Entries,cn=etc,dc=local'] 2019-01-17T11:00:45Z DEBUG only: updated value [u'cn=Definitions,cn=Managed Entries,cn=etc,dc=local'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:45Z DEBUG Managed Entries 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG Managed Entries 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:45Z DEBUG 1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:45Z DEBUG Managed Entries plugin 2019-01-17T11:00:45Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:45Z DEBUG libmanagedentries-plugin 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsSlapdPlugin 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsContainer 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:45Z DEBUG database 2019-01-17T11:00:45Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:45Z DEBUG 389 Project 2019-01-17T11:00:45Z DEBUG nsslapd-pluginConfigArea: 2019-01-17T11:00:45Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:45Z DEBUG betxnpreoperation 2019-01-17T11:00:45Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:45Z DEBUG mep_init 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG New entry: cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG nsContainer 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG Managed Entries 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG nsContainer 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG Managed Entries 2019-01-17T11:00:45Z ERROR Parent DN of cn=Managed Entries,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:45Z DEBUG New entry: cn=Templates,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=Templates,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG nsContainer 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG Templates 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=Templates,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG nsContainer 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG Templates 2019-01-17T11:00:45Z ERROR Parent DN of cn=Templates,cn=Managed Entries,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:45Z DEBUG New entry: cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG nsContainer 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG Definitions 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG nsContainer 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG Definitions 2019-01-17T11:00:45Z ERROR Parent DN of cn=Definitions,cn=Managed Entries,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:45Z DEBUG Parsing update file '/usr/share/ipa/updates/20-aci.update' 2019-01-17T11:00:45Z DEBUG New entry: cn=ng,cn=alt,dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=ng,cn=alt,dc=local 2019-01-17T11:00:45Z DEBUG add: '(targetfilter = "(objectClass=mepManagedEntry)")(targetattr = "*")(version 3.0; acl "Managed netgroups cannot be modified"; deny (write) userdn = "ldap:///all";)' to aci, current value [] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(targetfilter = "(objectClass=mepManagedEntry)")(targetattr = "*")(version 3.0; acl "Managed netgroups cannot be modified"; deny (write) userdn = "ldap:///all";)'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=ng,cn=alt,dc=local 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetfilter = "(objectClass=mepManagedEntry)")(targetattr = "*")(version 3.0; acl "Managed netgroups cannot be modified"; deny (write) userdn = "ldap:///all";) 2019-01-17T11:00:45Z ERROR Parent DN of cn=ng,cn=alt,dc=local may not exist, cannot create the entry 2019-01-17T11:00:45Z DEBUG New entry: cn=accounts,dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=accounts,dc=local 2019-01-17T11:00:45Z DEBUG add: '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)' to aci, current value [] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=accounts,dc=local 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";) 2019-01-17T11:00:45Z ERROR Add failure missing required attribute "objectclass" 2019-01-17T11:00:45Z DEBUG Updating existing entry: dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: dc=local 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG domain 2019-01-17T11:00:45Z DEBUG pilotObject 2019-01-17T11:00:45Z DEBUG info: 2019-01-17T11:00:45Z DEBUG IPA V2.0 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2019-01-17T11:00:45Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2019-01-17T11:00:45Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2019-01-17T11:00:45Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2019-01-17T11:00:45Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:00:45Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:00:45Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:00:45Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2019-01-17T11:00:45Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2019-01-17T11:00:45Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2019-01-17T11:00:45Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:00:45Z DEBUG dc: 2019-01-17T11:00:45Z DEBUG local 2019-01-17T11:00:45Z DEBUG add: '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: dc=local 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG domain 2019-01-17T11:00:45Z DEBUG pilotObject 2019-01-17T11:00:45Z DEBUG info: 2019-01-17T11:00:45Z DEBUG IPA V2.0 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2019-01-17T11:00:45Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2019-01-17T11:00:45Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2019-01-17T11:00:45Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:00:45Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:00:45Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:00:45Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2019-01-17T11:00:45Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2019-01-17T11:00:45Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2019-01-17T11:00:45Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:00:45Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2019-01-17T11:00:45Z DEBUG dc: 2019-01-17T11:00:45Z DEBUG local 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG New entry: cn=computers,cn=accounts,dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=computers,cn=accounts,dc=local 2019-01-17T11:00:45Z DEBUG add: '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";)' to aci, current value [] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";)'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=computers,cn=accounts,dc=local 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";) 2019-01-17T11:00:45Z ERROR Parent DN of cn=computers,cn=accounts,dc=local may not exist, cannot create the entry 2019-01-17T11:00:45Z DEBUG New entry: cn=computers,cn=accounts,dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=computers,cn=accounts,dc=local 2019-01-17T11:00:45Z DEBUG add: '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)' to aci, current value [] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=computers,cn=accounts,dc=local 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2019-01-17T11:00:45Z ERROR Parent DN of cn=computers,cn=accounts,dc=local may not exist, cannot create the entry 2019-01-17T11:00:45Z DEBUG Updating existing entry: dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: dc=local 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG domain 2019-01-17T11:00:45Z DEBUG pilotObject 2019-01-17T11:00:45Z DEBUG info: 2019-01-17T11:00:45Z DEBUG IPA V2.0 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2019-01-17T11:00:45Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2019-01-17T11:00:45Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2019-01-17T11:00:45Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2019-01-17T11:00:45Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:00:45Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:00:45Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:00:45Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2019-01-17T11:00:45Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2019-01-17T11:00:45Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2019-01-17T11:00:45Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:00:45Z DEBUG dc: 2019-01-17T11:00:45Z DEBUG local 2019-01-17T11:00:45Z DEBUG add: '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: dc=local 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG domain 2019-01-17T11:00:45Z DEBUG pilotObject 2019-01-17T11:00:45Z DEBUG info: 2019-01-17T11:00:45Z DEBUG IPA V2.0 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2019-01-17T11:00:45Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2019-01-17T11:00:45Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2019-01-17T11:00:45Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2019-01-17T11:00:45Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:00:45Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:00:45Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:00:45Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2019-01-17T11:00:45Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2019-01-17T11:00:45Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2019-01-17T11:00:45Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:00:45Z DEBUG dc: 2019-01-17T11:00:45Z DEBUG local 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Updating existing entry: dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: dc=local 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG domain 2019-01-17T11:00:45Z DEBUG pilotObject 2019-01-17T11:00:45Z DEBUG info: 2019-01-17T11:00:45Z DEBUG IPA V2.0 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2019-01-17T11:00:45Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2019-01-17T11:00:45Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2019-01-17T11:00:45Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2019-01-17T11:00:45Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:00:45Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:00:45Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:00:45Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2019-01-17T11:00:45Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2019-01-17T11:00:45Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2019-01-17T11:00:45Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:00:45Z DEBUG dc: 2019-01-17T11:00:45Z DEBUG local 2019-01-17T11:00:45Z DEBUG add: '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: dc=local 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG domain 2019-01-17T11:00:45Z DEBUG pilotObject 2019-01-17T11:00:45Z DEBUG info: 2019-01-17T11:00:45Z DEBUG IPA V2.0 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2019-01-17T11:00:45Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2019-01-17T11:00:45Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2019-01-17T11:00:45Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2019-01-17T11:00:45Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:00:45Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:00:45Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:00:45Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2019-01-17T11:00:45Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2019-01-17T11:00:45Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2019-01-17T11:00:45Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:00:45Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:00:45Z DEBUG dc: 2019-01-17T11:00:45Z DEBUG local 2019-01-17T11:00:45Z DEBUG [(0, u'aci', [u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)'])] 2019-01-17T11:00:45Z DEBUG Updated 1 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG New entry: dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: dc=local 2019-01-17T11:00:45Z DEBUG add: '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)' to aci, current value [] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: dc=local 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:00:45Z ERROR Add failure missing required attribute "objectclass" 2019-01-17T11:00:45Z DEBUG New entry: cn=replicas,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=replicas,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG remove: '(targetfilter="(objectclass=nsContainer)")(version 3.0; acl "Deny read access to replica configuration"; deny(read, search, compare) userdn = "ldap:///anyone";)' from aci, current value [] 2019-01-17T11:00:45Z DEBUG remove: '(targetfilter="(objectclass=nsContainer)")(version 3.0; acl "Deny read access to replica configuration"; deny(read, search, compare) userdn = "ldap:///anyone";)' not in aci 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=replicas,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG New entry: cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG add: '(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)' to aci, current value [] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2019-01-17T11:00:45Z ERROR Parent DN of cn=masters,cn=ipa,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:45Z DEBUG New entry: cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG add: '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=local";)' to aci, current value [] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=local";)'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=local";) 2019-01-17T11:00:45Z ERROR Parent DN of cn=masters,cn=ipa,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:45Z DEBUG New entry: cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG add: '(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=local")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=local";)' to aci, current value [] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=local")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=local";)'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=local")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=local";) 2019-01-17T11:00:45Z ERROR Parent DN of cn=sysaccounts,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:45Z DEBUG New entry: cn=kerberos,dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=kerberos,dc=local 2019-01-17T11:00:45Z DEBUG add: '(targetattr = "cn || objectclass")(targetfilter = "(|(objectclass=krbrealmcontainer)(objectclass=krbcontainer))")(version 3.0;acl "Anonymous read access to Kerberos containers";allow (read,compare,search) userdn = "ldap:///anyone";)' to aci, current value [] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(targetattr = "cn || objectclass")(targetfilter = "(|(objectclass=krbrealmcontainer)(objectclass=krbcontainer))")(version 3.0;acl "Anonymous read access to Kerberos containers";allow (read,compare,search) userdn = "ldap:///anyone";)'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=kerberos,dc=local 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetattr = "cn || objectclass")(targetfilter = "(|(objectclass=krbrealmcontainer)(objectclass=krbcontainer))")(version 3.0;acl "Anonymous read access to Kerberos containers";allow (read,compare,search) userdn = "ldap:///anyone";) 2019-01-17T11:00:45Z ERROR Parent DN of cn=kerberos,dc=local may not exist, cannot create the entry 2019-01-17T11:00:45Z DEBUG New entry: dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: dc=local 2019-01-17T11:00:45Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || krbTicketFlags || ipaUniqueId || memberOf || serverHostName || enrolledBy")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' from aci, current value [] 2019-01-17T11:00:45Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || krbTicketFlags || ipaUniqueId || memberOf || serverHostName || enrolledBy")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' not in aci 2019-01-17T11:00:45Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || krbTicketFlags || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' from aci, current value [] 2019-01-17T11:00:45Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || krbTicketFlags || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' not in aci 2019-01-17T11:00:45Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' from aci, current value [] 2019-01-17T11:00:45Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' not in aci 2019-01-17T11:00:45Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' from aci, current value [] 2019-01-17T11:00:45Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' not in aci 2019-01-17T11:00:45Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' from aci, current value [] 2019-01-17T11:00:45Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' not in aci 2019-01-17T11:00:45Z DEBUG add: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' to aci, current value [] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:00:45Z DEBUG remove: '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' from aci, current value [u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:00:45Z DEBUG remove: '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' not in aci 2019-01-17T11:00:45Z DEBUG remove: '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' from aci, current value [u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:00:45Z DEBUG remove: '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' not in aci 2019-01-17T11:00:45Z DEBUG add: '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' to aci, current value [u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:00:45Z DEBUG add: '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' to aci, current value [u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:00:45Z DEBUG add: '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' to aci, current value [u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:00:45Z DEBUG add: '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' to aci, current value [u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: dc=local 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:00:45Z ERROR Add failure missing required attribute "objectclass" 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=tasks,cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=tasks,cn=config 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetattr=*)(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr=*)(version 3.0; acl "cert manager: Run tasks after replica re-initialization"; allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:00:45Z DEBUG (targetattr="*")(version 3.0; acl "Admin can read all tasks"; allow (read, compare, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "*")(target = "ldap:///cn=*,cn=automember rebuild membership,cn=tasks,cn=config")(version 3.0;acl "permission:System: Read Automember Tasks";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Automember Tasks,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG tasks 2019-01-17T11:00:45Z DEBUG add: '(targetattr="*")(version 3.0; acl "Admin can read all tasks"; allow (read, compare, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' to aci, current value [u'(targetattr=*)(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(version 3.0; acl "cert manager: Run tasks after replica re-initialization"; allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(targetattr="*")(version 3.0; acl "Admin can read all tasks"; allow (read, compare, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "*")(target = "ldap:///cn=*,cn=automember rebuild membership,cn=tasks,cn=config")(version 3.0;acl "permission:System: Read Automember Tasks";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Automember Tasks,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(targetattr=*)(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(version 3.0; acl "cert manager: Run tasks after replica re-initialization"; allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(targetattr = "*")(target = "ldap:///cn=*,cn=automember rebuild membership,cn=tasks,cn=config")(version 3.0;acl "permission:System: Read Automember Tasks";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Automember Tasks,cn=permissions,cn=pbac,dc=local";)', u'(targetattr="*")(version 3.0; acl "Admin can read all tasks"; allow (read, compare, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=tasks,cn=config 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetattr=*)(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr=*)(version 3.0; acl "cert manager: Run tasks after replica re-initialization"; allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:00:45Z DEBUG (targetattr = "*")(target = "ldap:///cn=*,cn=automember rebuild membership,cn=tasks,cn=config")(version 3.0;acl "permission:System: Read Automember Tasks";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Automember Tasks,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr="*")(version 3.0; acl "Admin can read all tasks"; allow (read, compare, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG tasks 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=mapping tree,cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=mapping tree,cn=config 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG mapping tree 2019-01-17T11:00:45Z DEBUG add: '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)' to aci, current value [u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=mapping tree,cn=config 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG mapping tree 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=mapping tree,cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=mapping tree,cn=config 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG mapping tree 2019-01-17T11:00:45Z DEBUG add: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";)' to aci, current value [u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:00:45Z DEBUG add: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)' to aci, current value [u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:00:45Z DEBUG add: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";)' to aci, current value [u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:00:45Z DEBUG add: '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=local";)' to aci, current value [u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=mapping tree,cn=config 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG mapping tree 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=dc\=local,cn=mapping tree,cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=dc\=local,cn=mapping tree,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-state: 2019-01-17T11:00:45Z DEBUG backend 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsMappingTree 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG "dc=local" 2019-01-17T11:00:45Z DEBUG nsslapd-backend: 2019-01-17T11:00:45Z DEBUG userRoot 2019-01-17T11:00:45Z DEBUG remove: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";)' from aci, current value [] 2019-01-17T11:00:45Z DEBUG remove: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";)' not in aci 2019-01-17T11:00:45Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)' from aci, current value [] 2019-01-17T11:00:45Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)' not in aci 2019-01-17T11:00:45Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";)' from aci, current value [] 2019-01-17T11:00:45Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";)' not in aci 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=dc\=local,cn=mapping tree,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-state: 2019-01-17T11:00:45Z DEBUG backend 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsMappingTree 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG "dc=local" 2019-01-17T11:00:45Z DEBUG nsslapd-backend: 2019-01-17T11:00:45Z DEBUG userRoot 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=o\=ipaca,cn=mapping tree,cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=o\=ipaca,cn=mapping tree,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-state: 2019-01-17T11:00:45Z DEBUG Backend 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsMappingTree 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetattr=*)(version 3.0;acl "cert manager: Add Replication Agreements";allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:00:45Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "cert manager: Modify Replication Agreements"; allow (read, write, search) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:00:45Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "cert manager: Remove Replication Agreements";allow (delete) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG o=ipaca 2019-01-17T11:00:45Z DEBUG nsslapd-backend: 2019-01-17T11:00:45Z DEBUG ipaca 2019-01-17T11:00:45Z DEBUG remove: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";)' from aci, current value [u'(targetattr=*)(version 3.0;acl "cert manager: Add Replication Agreements";allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "cert manager: Modify Replication Agreements"; allow (read, write, search) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "cert manager: Remove Replication Agreements";allow (delete) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)'] 2019-01-17T11:00:45Z DEBUG remove: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";)' not in aci 2019-01-17T11:00:45Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)' from aci, current value [u'(targetattr=*)(version 3.0;acl "cert manager: Add Replication Agreements";allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "cert manager: Modify Replication Agreements"; allow (read, write, search) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "cert manager: Remove Replication Agreements";allow (delete) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)'] 2019-01-17T11:00:45Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)' not in aci 2019-01-17T11:00:45Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";)' from aci, current value [u'(targetattr=*)(version 3.0;acl "cert manager: Add Replication Agreements";allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "cert manager: Modify Replication Agreements"; allow (read, write, search) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "cert manager: Remove Replication Agreements";allow (delete) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)'] 2019-01-17T11:00:45Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";)' not in aci 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=o\=ipaca,cn=mapping tree,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-state: 2019-01-17T11:00:45Z DEBUG Backend 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsMappingTree 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetattr=*)(version 3.0;acl "cert manager: Add Replication Agreements";allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:00:45Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "cert manager: Modify Replication Agreements"; allow (read, write, search) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:00:45Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "cert manager: Remove Replication Agreements";allow (delete) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG o=ipaca 2019-01-17T11:00:45Z DEBUG nsslapd-backend: 2019-01-17T11:00:45Z DEBUG ipaca 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG Updating existing entry: cn=config 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-betype: 2019-01-17T11:00:45Z DEBUG ldbm database 2019-01-17T11:00:45Z DEBUG nsslapd-nagle: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-referralmode: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:00:45Z DEBUG 64 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 500 2019-01-17T11:00:45Z DEBUG passwordMinAlphas: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-readonly: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordLegacyPolicy: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:00:45Z DEBUG allowed 2019-01-17T11:00:45Z DEBUG passwordMinUppers: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-plugin: 2019-01-17T11:00:45Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:00:45Z DEBUG 20971520 2019-01-17T11:00:45Z DEBUG nsslapd-timelimit: 2019-01-17T11:00:45Z DEBUG 3600 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinTokenLength: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordMinAge: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:00:45Z DEBUG 60 2019-01-17T11:00:45Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:00:45Z DEBUG 1024 2019-01-17T11:00:45Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordInHistory: 2019-01-17T11:00:45Z DEBUG 6 2019-01-17T11:00:45Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-conntablesize: 2019-01-17T11:00:45Z DEBUG 16384 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-saslpath: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG passwordMaxAge: 2019-01-17T11:00:45Z DEBUG 8640000 2019-01-17T11:00:45Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:00:45Z DEBUG gidNumber 2019-01-17T11:00:45Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG day 2019-01-17T11:00:45Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-csnlogging: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-tmpdir: 2019-01-17T11:00:45Z DEBUG /tmp 2019-01-17T11:00:45Z DEBUG passwordResetFailureCount: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-counters: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-svrtab: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-minssf: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-schemadir: 2019-01-17T11:00:45Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:00:45Z DEBUG nsslapd-localuser: 2019-01-17T11:00:45Z DEBUG dirsrv 2019-01-17T11:00:45Z DEBUG nsslapd-security: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordChange: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-port 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:00:45Z DEBUG passwordMaxFailure: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:00:45Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:00:45Z DEBUG 128 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:00:45Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-rootdn: 2019-01-17T11:00:45Z DEBUG cn=Directory Manager 2019-01-17T11:00:45Z DEBUG nsslapd-ldifdir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:00:45Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordMustChange: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordExp: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-logging-backend: 2019-01-17T11:00:45Z DEBUG dirsrv-log 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:45Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:00:45Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:00:45Z DEBUG cn=Directory Manager 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinLength: 2019-01-17T11:00:45Z DEBUG 8 2019-01-17T11:00:45Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-idletimeout: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-securePort: 2019-01-17T11:00:45Z DEBUG 636 2019-01-17T11:00:45Z DEBUG nsslapd-snmp-index: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG config 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapdConfig 2019-01-17T11:00:45Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordSendExpiringTime: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-hash-filters: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:00:45Z DEBUG next 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-listenhost: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordCheckSyntax: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordGraceLimit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG passwordWarning: 2019-01-17T11:00:45Z DEBUG 86400 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-instancedir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-config: 2019-01-17T11:00:45Z DEBUG cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-versionstring: 2019-01-17T11:00:45Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:00:45Z DEBUG 256 2019-01-17T11:00:45Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:00:45Z DEBUG SSHA512 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordLockout: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-lockdir: 2019-01-17T11:00:45Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-certdir: 2019-01-17T11:00:45Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 10 2019-01-17T11:00:45Z DEBUG nsslapd-backendconfig: 2019-01-17T11:00:45Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-threadnumber: 2019-01-17T11:00:45Z DEBUG 24 2019-01-17T11:00:45Z DEBUG nsslapd-schemamod: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-localhost: 2019-01-17T11:00:45Z DEBUG centos75.local 2019-01-17T11:00:45Z DEBUG nsslapd-bakdir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:00:45Z DEBUG passwordMin8bit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:00:45Z DEBUG uidNumber 2019-01-17T11:00:45Z DEBUG nsslapd-validate-cert: 2019-01-17T11:00:45Z DEBUG warn 2019-01-17T11:00:45Z DEBUG passwordMinCategories: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG passwordMinLowers: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordAdminDN: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordMinSpecials: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-lastmod: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:00:45Z DEBUG 40 2019-01-17T11:00:45Z DEBUG passwordMaxRepeats: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:00:45Z DEBUG -1 2019-01-17T11:00:45Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG nsslapd-result-tweak: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG passwordUnlock: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-schemacheck: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-maxbersize: 2019-01-17T11:00:45Z DEBUG 209715200 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:00:45Z DEBUG dc=example,dc=com 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-localssf: 2019-01-17T11:00:45Z DEBUG 71 2019-01-17T11:00:45Z DEBUG nsslapd-sizelimit: 2019-01-17T11:00:45Z DEBUG 2000 2019-01-17T11:00:45Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG passwordLockoutDuration: 2019-01-17T11:00:45Z DEBUG 3600 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-port: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:00:45Z DEBUG cn=schema 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG cn=monitor 2019-01-17T11:00:45Z DEBUG cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-rootpw: 2019-01-17T11:00:45Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:00:45Z DEBUG 300000 2019-01-17T11:00:45Z DEBUG nsslapd-workingdir: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-rundir: 2019-01-17T11:00:45Z DEBUG /var/run/dirsrv 2019-01-17T11:00:45Z DEBUG nsslapd-schemareplace: 2019-01-17T11:00:45Z DEBUG replication-only 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:00:45Z DEBUG 16384 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:00:45Z DEBUG 10000 2019-01-17T11:00:45Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinDigits: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG passwordStorageScheme: 2019-01-17T11:00:45Z DEBUG SSHA512 2019-01-17T11:00:45Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG remove: '(targetattr != aci)(version 3.0; aci "replica admins read access"; allow (read, search, compare) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)' from aci, current value [u'(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";)', u'(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:00:45Z DEBUG remove: '(targetattr != aci)(version 3.0; aci "replica admins read access"; allow (read, search, compare) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)' not in aci 2019-01-17T11:00:45Z DEBUG remove: '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:System: Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Replication Agreements,cn=permissions,cn=pbac,dc=local";)' from aci, current value [u'(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";)', u'(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:00:45Z DEBUG remove: '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:System: Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Replication Agreements,cn=permissions,cn=pbac,dc=local";)' not in aci 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-betype: 2019-01-17T11:00:45Z DEBUG ldbm database 2019-01-17T11:00:45Z DEBUG nsslapd-nagle: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-referralmode: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:00:45Z DEBUG 64 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 500 2019-01-17T11:00:45Z DEBUG passwordMinAlphas: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-readonly: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordLegacyPolicy: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:00:45Z DEBUG allowed 2019-01-17T11:00:45Z DEBUG passwordMinUppers: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-plugin: 2019-01-17T11:00:45Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:00:45Z DEBUG 20971520 2019-01-17T11:00:45Z DEBUG nsslapd-timelimit: 2019-01-17T11:00:45Z DEBUG 3600 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinTokenLength: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordMinAge: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:00:45Z DEBUG 60 2019-01-17T11:00:45Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:00:45Z DEBUG 1024 2019-01-17T11:00:45Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordInHistory: 2019-01-17T11:00:45Z DEBUG 6 2019-01-17T11:00:45Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-conntablesize: 2019-01-17T11:00:45Z DEBUG 16384 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-saslpath: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG passwordMaxAge: 2019-01-17T11:00:45Z DEBUG 8640000 2019-01-17T11:00:45Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:00:45Z DEBUG gidNumber 2019-01-17T11:00:45Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG day 2019-01-17T11:00:45Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-csnlogging: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-tmpdir: 2019-01-17T11:00:45Z DEBUG /tmp 2019-01-17T11:00:45Z DEBUG passwordResetFailureCount: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-counters: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-svrtab: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-minssf: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-schemadir: 2019-01-17T11:00:45Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:00:45Z DEBUG nsslapd-localuser: 2019-01-17T11:00:45Z DEBUG dirsrv 2019-01-17T11:00:45Z DEBUG nsslapd-security: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordChange: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-port 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:00:45Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:00:45Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:00:45Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:00:45Z DEBUG passwordMaxFailure: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:00:45Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:00:45Z DEBUG 128 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:00:45Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-rootdn: 2019-01-17T11:00:45Z DEBUG cn=Directory Manager 2019-01-17T11:00:45Z DEBUG nsslapd-ldifdir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:00:45Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordMustChange: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordExp: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-logging-backend: 2019-01-17T11:00:45Z DEBUG dirsrv-log 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:45Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:00:45Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:00:45Z DEBUG cn=Directory Manager 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinLength: 2019-01-17T11:00:45Z DEBUG 8 2019-01-17T11:00:45Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-idletimeout: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:00:45Z DEBUG week 2019-01-17T11:00:45Z DEBUG nsslapd-securePort: 2019-01-17T11:00:45Z DEBUG 636 2019-01-17T11:00:45Z DEBUG nsslapd-snmp-index: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG config 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG nsslapdConfig 2019-01-17T11:00:45Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordSendExpiringTime: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-hash-filters: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:00:45Z DEBUG next 2019-01-17T11:00:45Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:00:45Z DEBUG -10 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-listenhost: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordCheckSyntax: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordGraceLimit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG passwordWarning: 2019-01-17T11:00:45Z DEBUG 86400 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-instancedir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-config: 2019-01-17T11:00:45Z DEBUG cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-versionstring: 2019-01-17T11:00:45Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:00:45Z DEBUG 256 2019-01-17T11:00:45Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:00:45Z DEBUG SSHA512 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG passwordLockout: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-lockdir: 2019-01-17T11:00:45Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-certdir: 2019-01-17T11:00:45Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 10 2019-01-17T11:00:45Z DEBUG nsslapd-backendconfig: 2019-01-17T11:00:45Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-threadnumber: 2019-01-17T11:00:45Z DEBUG 24 2019-01-17T11:00:45Z DEBUG nsslapd-schemamod: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-localhost: 2019-01-17T11:00:45Z DEBUG centos75.local 2019-01-17T11:00:45Z DEBUG nsslapd-bakdir: 2019-01-17T11:00:45Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:00:45Z DEBUG passwordMin8bit: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:00:45Z DEBUG uidNumber 2019-01-17T11:00:45Z DEBUG nsslapd-validate-cert: 2019-01-17T11:00:45Z DEBUG warn 2019-01-17T11:00:45Z DEBUG passwordMinCategories: 2019-01-17T11:00:45Z DEBUG 3 2019-01-17T11:00:45Z DEBUG passwordMinLowers: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordAdminDN: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordMinSpecials: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-lastmod: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:00:45Z DEBUG 40 2019-01-17T11:00:45Z DEBUG passwordMaxRepeats: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:00:45Z DEBUG -1 2019-01-17T11:00:45Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:00:45Z DEBUG none 2019-01-17T11:00:45Z DEBUG nsslapd-result-tweak: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:00:45Z DEBUG month 2019-01-17T11:00:45Z DEBUG passwordUnlock: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-schemacheck: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-maxbersize: 2019-01-17T11:00:45Z DEBUG 209715200 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:00:45Z DEBUG dc=example,dc=com 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-localssf: 2019-01-17T11:00:45Z DEBUG 71 2019-01-17T11:00:45Z DEBUG nsslapd-sizelimit: 2019-01-17T11:00:45Z DEBUG 2000 2019-01-17T11:00:45Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:00:45Z DEBUG dc=local 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:00:45Z DEBUG 2097152 2019-01-17T11:00:45Z DEBUG passwordLockoutDuration: 2019-01-17T11:00:45Z DEBUG 3600 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-port: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:00:45Z DEBUG 100 2019-01-17T11:00:45Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:00:45Z DEBUG cn=schema 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG cn=monitor 2019-01-17T11:00:45Z DEBUG cn=config 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:00:45Z DEBUG 1 2019-01-17T11:00:45Z DEBUG nsslapd-auditlog: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:00:45Z DEBUG 600 2019-01-17T11:00:45Z DEBUG nsslapd-rootpw: 2019-01-17T11:00:45Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:00:45Z DEBUG 300000 2019-01-17T11:00:45Z DEBUG nsslapd-workingdir: 2019-01-17T11:00:45Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:00:45Z DEBUG 2019-01-17T11:00:45Z DEBUG nsslapd-rundir: 2019-01-17T11:00:45Z DEBUG /var/run/dirsrv 2019-01-17T11:00:45Z DEBUG nsslapd-schemareplace: 2019-01-17T11:00:45Z DEBUG replication-only 2019-01-17T11:00:45Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:00:45Z DEBUG 16384 2019-01-17T11:00:45Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:00:45Z DEBUG 10000 2019-01-17T11:00:45Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:00:45Z DEBUG off 2019-01-17T11:00:45Z DEBUG passwordMinDigits: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:00:45Z DEBUG 5 2019-01-17T11:00:45Z DEBUG passwordStorageScheme: 2019-01-17T11:00:45Z DEBUG SSHA512 2019-01-17T11:00:45Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:00:45Z DEBUG on 2019-01-17T11:00:45Z DEBUG [] 2019-01-17T11:00:45Z DEBUG Updated 0 2019-01-17T11:00:45Z DEBUG Done 2019-01-17T11:00:45Z DEBUG New entry: dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: dc=local 2019-01-17T11:00:45Z DEBUG remove: '(targetattr = "*")(target = "ldap:///cn=*,cn=roles,cn=accounts,dc=local")(version 3.0; acl "No anonymous access to roles"; deny (read,search,compare) userdn != "ldap:///all";)' from aci, current value [] 2019-01-17T11:00:45Z DEBUG remove: '(targetattr = "*")(target = "ldap:///cn=*,cn=roles,cn=accounts,dc=local")(version 3.0; acl "No anonymous access to roles"; deny (read,search,compare) userdn != "ldap:///all";)' not in aci 2019-01-17T11:00:45Z DEBUG remove: '(targetattr = "memberOf || memberHost || memberUser")(version 3.0; acl "No anonymous access to member information"; deny (read,search,compare) userdn != "ldap:///all";)' from aci, current value [] 2019-01-17T11:00:45Z DEBUG remove: '(targetattr = "memberOf || memberHost || memberUser")(version 3.0; acl "No anonymous access to member information"; deny (read,search,compare) userdn != "ldap:///all";)' not in aci 2019-01-17T11:00:45Z DEBUG remove: '(targetattr = "*")(target = "ldap:///cn=*,ou=SUDOers,dc=local")(version 3.0; acl "No anonymous access to sudo"; deny (read,search,compare) userdn != "ldap:///all";)' from aci, current value [] 2019-01-17T11:00:45Z DEBUG remove: '(targetattr = "*")(target = "ldap:///cn=*,ou=SUDOers,dc=local")(version 3.0; acl "No anonymous access to sudo"; deny (read,search,compare) userdn != "ldap:///all";)' not in aci 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: dc=local 2019-01-17T11:00:45Z DEBUG New entry: cn=hbac,dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=hbac,dc=local 2019-01-17T11:00:45Z DEBUG remove: '(targetattr = "*")(version 3.0; acl "No anonymous access to hbac"; deny (read,search,compare) userdn != "ldap:///all";)' from aci, current value [] 2019-01-17T11:00:45Z DEBUG remove: '(targetattr = "*")(version 3.0; acl "No anonymous access to hbac"; deny (read,search,compare) userdn != "ldap:///all";)' not in aci 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=hbac,dc=local 2019-01-17T11:00:45Z DEBUG New entry: cn=sudo,dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=sudo,dc=local 2019-01-17T11:00:45Z DEBUG remove: '(targetattr = "*")(version 3.0; acl "No anonymous access to sudo"; deny (read,search,compare) userdn != "ldap:///all";)' from aci, current value [] 2019-01-17T11:00:45Z DEBUG remove: '(targetattr = "*")(version 3.0; acl "No anonymous access to sudo"; deny (read,search,compare) userdn != "ldap:///all";)' not in aci 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=sudo,dc=local 2019-01-17T11:00:45Z DEBUG New entry: cn=accounts,dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=accounts,dc=local 2019-01-17T11:00:45Z DEBUG add: '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)' to aci, current value [] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)'] 2019-01-17T11:00:45Z DEBUG add: '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)' to aci, current value [u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2019-01-17T11:00:45Z DEBUG add: '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)' to aci, current value [u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)'] 2019-01-17T11:00:45Z DEBUG add: '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)' to aci, current value [u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)'] 2019-01-17T11:00:45Z DEBUG add: '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)' to aci, current value [u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)'] 2019-01-17T11:00:45Z DEBUG add: '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' to aci, current value [u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:00:45Z DEBUG add: '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)' to aci, current value [u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=accounts,dc=local 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";) 2019-01-17T11:00:45Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2019-01-17T11:00:45Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";) 2019-01-17T11:00:45Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";) 2019-01-17T11:00:45Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";) 2019-01-17T11:00:45Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:00:45Z DEBUG (targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";) 2019-01-17T11:00:45Z ERROR Parent DN of cn=accounts,dc=local may not exist, cannot create the entry 2019-01-17T11:00:45Z DEBUG New entry: dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: dc=local 2019-01-17T11:00:45Z DEBUG add: '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)' to aci, current value [] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: dc=local 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2019-01-17T11:00:45Z ERROR Add failure missing required attribute "objectclass" 2019-01-17T11:00:45Z DEBUG New entry: cn=services,cn=accounts,dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=services,cn=accounts,dc=local 2019-01-17T11:00:45Z DEBUG remove: '(target = "ldap:///krbprincipalname=*/($dn)@LOCAL,cn=services,cn=accounts,dc=local")(targetfilter = "(objectClass=ipaKrbPrincipal)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)' from aci, current value [] 2019-01-17T11:00:45Z DEBUG remove: '(target = "ldap:///krbprincipalname=*/($dn)@LOCAL,cn=services,cn=accounts,dc=local")(targetfilter = "(objectClass=ipaKrbPrincipal)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)' not in aci 2019-01-17T11:00:45Z DEBUG add: '(target = "ldap:///krbprincipalname=*/($dn)@LOCAL,cn=services,cn=accounts,dc=local")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)' to aci, current value [] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(target = "ldap:///krbprincipalname=*/($dn)@LOCAL,cn=services,cn=accounts,dc=local")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)'] 2019-01-17T11:00:45Z DEBUG add: '(target = "ldap:///krbprincipalname=*/($dn)@LOCAL,cn=services,cn=accounts,dc=local")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)' to aci, current value [u'(target = "ldap:///krbprincipalname=*/($dn)@LOCAL,cn=services,cn=accounts,dc=local")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(target = "ldap:///krbprincipalname=*/($dn)@LOCAL,cn=services,cn=accounts,dc=local")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///krbprincipalname=*/($dn)@LOCAL,cn=services,cn=accounts,dc=local")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=services,cn=accounts,dc=local 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (target = "ldap:///krbprincipalname=*/($dn)@LOCAL,cn=services,cn=accounts,dc=local")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:00:45Z DEBUG (target = "ldap:///krbprincipalname=*/($dn)@LOCAL,cn=services,cn=accounts,dc=local")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:00:45Z ERROR Parent DN of cn=services,cn=accounts,dc=local may not exist, cannot create the entry 2019-01-17T11:00:45Z DEBUG New entry: cn=ranges,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=ranges,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG add: '(target = "ldap:///cn=*,cn=ranges,cn=etc,dc=local")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@LOCAL,cn=services,cn=accounts,dc=local" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)' to aci, current value [] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(target = "ldap:///cn=*,cn=ranges,cn=etc,dc=local")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@LOCAL,cn=services,cn=accounts,dc=local" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=ranges,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (target = "ldap:///cn=*,cn=ranges,cn=etc,dc=local")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@LOCAL,cn=services,cn=accounts,dc=local" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";) 2019-01-17T11:00:45Z ERROR Parent DN of cn=ranges,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:45Z DEBUG New entry: cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG add: '(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=local")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)' to aci, current value [] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=local")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=local")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";) 2019-01-17T11:00:45Z ERROR Parent DN of cn=sysaccounts,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:45Z DEBUG New entry: cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG add: '(target = "ldap:///cn=replication,cn=etc,dc=local")(targetattr = "nsDS5ReplicaId")(version 3.0; acl "IPA server hosts can change replica ID"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)' to aci, current value [] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(target = "ldap:///cn=replication,cn=etc,dc=local")(targetattr = "nsDS5ReplicaId")(version 3.0; acl "IPA server hosts can change replica ID"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (target = "ldap:///cn=replication,cn=etc,dc=local")(targetattr = "nsDS5ReplicaId")(version 3.0; acl "IPA server hosts can change replica ID"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";) 2019-01-17T11:00:45Z ERROR Parent DN of cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:45Z DEBUG New entry: cn=ipa,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=ipa,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG add: '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)' to aci, current value [] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)'] 2019-01-17T11:00:45Z DEBUG add: '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)' to aci, current value [u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=ipa,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:00:45Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:00:45Z ERROR Parent DN of cn=ipa,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:45Z DEBUG New entry: cn=ipa,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=ipa,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG add: '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)' to aci, current value [] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)'] 2019-01-17T11:00:45Z DEBUG add: '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)' to aci, current value [u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)'] 2019-01-17T11:00:45Z DEBUG add: '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LOCAL,cn=services,cn=accounts,dc=local";)' to aci, current value [u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)'] 2019-01-17T11:00:45Z DEBUG add: updated value [u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LOCAL,cn=services,cn=accounts,dc=local";)'] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=ipa,cn=etc,dc=local 2019-01-17T11:00:45Z DEBUG aci: 2019-01-17T11:00:45Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:00:45Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:00:45Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LOCAL,cn=services,cn=accounts,dc=local";) 2019-01-17T11:00:45Z ERROR Parent DN of cn=ipa,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:45Z DEBUG New entry: krbPrincipalName=WELLKNOWN/ANONYMOUS@LOCAL,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: krbPrincipalName=WELLKNOWN/ANONYMOUS@LOCAL,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:00:45Z DEBUG addifexist: 'ipaAllowedOperations' to objectclass, current value [] 2019-01-17T11:00:45Z DEBUG addifexist: '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)' to aci, current value [] 2019-01-17T11:00:45Z DEBUG addifexist: 'cn=ipaservers,cn=hostgroups,cn=accounts,dc=local' to ipaAllowedToPerform;read_keys, current value [] 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: krbPrincipalName=WELLKNOWN/ANONYMOUS@LOCAL,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:00:45Z DEBUG Parsing update file '/usr/share/ipa/updates/20-default_password_policy.update' 2019-01-17T11:00:45Z DEBUG New entry: cn=Default Host Password Policy,cn=computers,cn=accounts,dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=Default Host Password Policy,cn=computers,cn=accounts,dc=local 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG Default Host Password Policy 2019-01-17T11:00:45Z DEBUG krbPwdHistoryLength: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG krbPwdPolicy 2019-01-17T11:00:45Z DEBUG nsContainer 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG krbPwdMinDiffChars: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG krbPwdMinLength: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG krbPwdLockoutDuration: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG krbPwdMaxFailure: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG krbMaxPwdLife: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG krbPwdFailureCountInterval: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG krbMinPwdLife: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=Default Host Password Policy,cn=computers,cn=accounts,dc=local 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG Default Host Password Policy 2019-01-17T11:00:45Z DEBUG krbPwdHistoryLength: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG krbPwdPolicy 2019-01-17T11:00:45Z DEBUG nsContainer 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG krbPwdMinDiffChars: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG krbPwdMinLength: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG krbPwdLockoutDuration: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG krbPwdMaxFailure: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG krbMaxPwdLife: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG krbPwdFailureCountInterval: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG krbMinPwdLife: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z ERROR Parent DN of cn=Default Host Password Policy,cn=computers,cn=accounts,dc=local may not exist, cannot create the entry 2019-01-17T11:00:45Z DEBUG New entry: cn=Default Service Password Policy,cn=services,cn=accounts,dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=Default Service Password Policy,cn=services,cn=accounts,dc=local 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG Default Service Password Policy 2019-01-17T11:00:45Z DEBUG krbPwdHistoryLength: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG krbPwdPolicy 2019-01-17T11:00:45Z DEBUG nsContainer 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG krbPwdMinDiffChars: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG krbPwdMinLength: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG krbPwdLockoutDuration: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG krbPwdMaxFailure: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG krbMaxPwdLife: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG krbPwdFailureCountInterval: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG krbMinPwdLife: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=Default Service Password Policy,cn=services,cn=accounts,dc=local 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG Default Service Password Policy 2019-01-17T11:00:45Z DEBUG krbPwdHistoryLength: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG krbPwdPolicy 2019-01-17T11:00:45Z DEBUG nsContainer 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG krbPwdMinDiffChars: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG krbPwdMinLength: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG krbPwdLockoutDuration: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG krbPwdMaxFailure: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG krbMaxPwdLife: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG krbPwdFailureCountInterval: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG krbMinPwdLife: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z ERROR Parent DN of cn=Default Service Password Policy,cn=services,cn=accounts,dc=local may not exist, cannot create the entry 2019-01-17T11:00:45Z DEBUG New entry: cn=Kerberos Service Password Policy,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=Kerberos Service Password Policy,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG nsContainer 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG Kerberos Service Password Policy 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=Kerberos Service Password Policy,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG nsContainer 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG Kerberos Service Password Policy 2019-01-17T11:00:45Z ERROR Parent DN of cn=Kerberos Service Password Policy,cn=LOCAL,cn=kerberos,dc=local may not exist, cannot create the entry 2019-01-17T11:00:45Z DEBUG New entry: cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG Default Kerberos Service Password Policy 2019-01-17T11:00:45Z DEBUG krbPwdHistoryLength: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG krbPwdPolicy 2019-01-17T11:00:45Z DEBUG nsContainer 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG krbPwdMinDiffChars: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG krbPwdMinLength: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG krbPwdLockoutDuration: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG krbPwdMaxFailure: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG krbMaxPwdLife: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG krbPwdFailureCountInterval: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG krbMinPwdLife: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG Default Kerberos Service Password Policy 2019-01-17T11:00:45Z DEBUG krbPwdHistoryLength: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG objectClass: 2019-01-17T11:00:45Z DEBUG krbPwdPolicy 2019-01-17T11:00:45Z DEBUG nsContainer 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG krbPwdMinDiffChars: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG krbPwdMinLength: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG krbPwdLockoutDuration: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG krbPwdMaxFailure: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG krbMaxPwdLife: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG krbPwdFailureCountInterval: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z DEBUG krbMinPwdLife: 2019-01-17T11:00:45Z DEBUG 0 2019-01-17T11:00:45Z ERROR Parent DN of cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=LOCAL,cn=kerberos,dc=local may not exist, cannot create the entry 2019-01-17T11:00:45Z DEBUG New entry: cn=cosTemplates,cn=computers,cn=accounts,dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=cosTemplates,cn=computers,cn=accounts,dc=local 2019-01-17T11:00:45Z DEBUG objectclass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsContainer 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG cosTemplates 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=cosTemplates,cn=computers,cn=accounts,dc=local 2019-01-17T11:00:45Z DEBUG objectclass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG nsContainer 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG cosTemplates 2019-01-17T11:00:45Z ERROR Parent DN of cn=cosTemplates,cn=computers,cn=accounts,dc=local may not exist, cannot create the entry 2019-01-17T11:00:45Z DEBUG New entry: cn=Default Password Policy,cn=cosTemplates,cn=computers,cn=accounts,dc=local 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Initial value 2019-01-17T11:00:45Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=computers,cn=accounts,dc=local 2019-01-17T11:00:45Z DEBUG objectclass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG cosTemplate 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG krbContainer 2019-01-17T11:00:45Z DEBUG krbPwdPolicyReference: 2019-01-17T11:00:45Z DEBUG cn=Default Host Password Policy,cn=computers,cn=accounts,dc=local 2019-01-17T11:00:45Z DEBUG cosPriority: 2019-01-17T11:00:45Z DEBUG 10000000000 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG Default Password Policy 2019-01-17T11:00:45Z DEBUG --------------------------------------------- 2019-01-17T11:00:45Z DEBUG Final value after applying updates 2019-01-17T11:00:45Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=computers,cn=accounts,dc=local 2019-01-17T11:00:45Z DEBUG objectclass: 2019-01-17T11:00:45Z DEBUG top 2019-01-17T11:00:45Z DEBUG cosTemplate 2019-01-17T11:00:45Z DEBUG extensibleObject 2019-01-17T11:00:45Z DEBUG krbContainer 2019-01-17T11:00:45Z DEBUG krbPwdPolicyReference: 2019-01-17T11:00:45Z DEBUG cn=Default Host Password Policy,cn=computers,cn=accounts,dc=local 2019-01-17T11:00:45Z DEBUG cosPriority: 2019-01-17T11:00:45Z DEBUG 10000000000 2019-01-17T11:00:45Z DEBUG cn: 2019-01-17T11:00:45Z DEBUG Default Password Policy 2019-01-17T11:00:45Z ERROR Parent DN of cn=Default Password Policy,cn=cosTemplates,cn=computers,cn=accounts,dc=local may not exist, cannot create the entry 2019-01-17T11:00:46Z DEBUG New entry: cn=Default Password Policy,cn=computers,cn=accounts,dc=local 2019-01-17T11:00:46Z DEBUG --------------------------------------------- 2019-01-17T11:00:46Z DEBUG Initial value 2019-01-17T11:00:46Z DEBUG dn: cn=Default Password Policy,cn=computers,cn=accounts,dc=local 2019-01-17T11:00:46Z DEBUG objectClass: 2019-01-17T11:00:46Z DEBUG top 2019-01-17T11:00:46Z DEBUG ldapsubentry 2019-01-17T11:00:46Z DEBUG cosSuperDefinition 2019-01-17T11:00:46Z DEBUG cosPointerDefinition 2019-01-17T11:00:46Z DEBUG cosTemplateDn: 2019-01-17T11:00:46Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=computers,cn=accounts,dc=local 2019-01-17T11:00:46Z DEBUG description: 2019-01-17T11:00:46Z DEBUG Default Password Policy for Hosts 2019-01-17T11:00:46Z DEBUG cosAttribute: 2019-01-17T11:00:46Z DEBUG krbPwdPolicyReference default 2019-01-17T11:00:46Z DEBUG --------------------------------------------- 2019-01-17T11:00:46Z DEBUG Final value after applying updates 2019-01-17T11:00:46Z DEBUG dn: cn=Default Password Policy,cn=computers,cn=accounts,dc=local 2019-01-17T11:00:46Z DEBUG objectClass: 2019-01-17T11:00:46Z DEBUG top 2019-01-17T11:00:46Z DEBUG ldapsubentry 2019-01-17T11:00:46Z DEBUG cosSuperDefinition 2019-01-17T11:00:46Z DEBUG cosPointerDefinition 2019-01-17T11:00:46Z DEBUG cosTemplateDn: 2019-01-17T11:00:46Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=computers,cn=accounts,dc=local 2019-01-17T11:00:46Z DEBUG description: 2019-01-17T11:00:46Z DEBUG Default Password Policy for Hosts 2019-01-17T11:00:46Z DEBUG cosAttribute: 2019-01-17T11:00:46Z DEBUG krbPwdPolicyReference default 2019-01-17T11:00:46Z ERROR Parent DN of cn=Default Password Policy,cn=computers,cn=accounts,dc=local may not exist, cannot create the entry 2019-01-17T11:00:46Z DEBUG New entry: cn=cosTemplates,cn=services,cn=accounts,dc=local 2019-01-17T11:00:46Z DEBUG --------------------------------------------- 2019-01-17T11:00:46Z DEBUG Initial value 2019-01-17T11:00:46Z DEBUG dn: cn=cosTemplates,cn=services,cn=accounts,dc=local 2019-01-17T11:00:46Z DEBUG objectclass: 2019-01-17T11:00:46Z DEBUG top 2019-01-17T11:00:46Z DEBUG nsContainer 2019-01-17T11:00:46Z DEBUG cn: 2019-01-17T11:00:46Z DEBUG cosTemplates 2019-01-17T11:00:46Z DEBUG --------------------------------------------- 2019-01-17T11:00:46Z DEBUG Final value after applying updates 2019-01-17T11:00:46Z DEBUG dn: cn=cosTemplates,cn=services,cn=accounts,dc=local 2019-01-17T11:00:46Z DEBUG objectclass: 2019-01-17T11:00:46Z DEBUG top 2019-01-17T11:00:46Z DEBUG nsContainer 2019-01-17T11:00:46Z DEBUG cn: 2019-01-17T11:00:46Z DEBUG cosTemplates 2019-01-17T11:00:46Z ERROR Parent DN of cn=cosTemplates,cn=services,cn=accounts,dc=local may not exist, cannot create the entry 2019-01-17T11:00:46Z DEBUG New entry: cn=Default Password Policy,cn=cosTemplates,cn=services,cn=accounts,dc=local 2019-01-17T11:00:46Z DEBUG --------------------------------------------- 2019-01-17T11:00:46Z DEBUG Initial value 2019-01-17T11:00:46Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=services,cn=accounts,dc=local 2019-01-17T11:00:46Z DEBUG objectclass: 2019-01-17T11:00:46Z DEBUG top 2019-01-17T11:00:46Z DEBUG cosTemplate 2019-01-17T11:00:46Z DEBUG extensibleObject 2019-01-17T11:00:46Z DEBUG krbContainer 2019-01-17T11:00:46Z DEBUG krbPwdPolicyReference: 2019-01-17T11:00:46Z DEBUG cn=Default Service Password Policy,cn=services,cn=accounts,dc=local 2019-01-17T11:00:46Z DEBUG cosPriority: 2019-01-17T11:00:46Z DEBUG 10000000000 2019-01-17T11:00:46Z DEBUG cn: 2019-01-17T11:00:46Z DEBUG Default Password Policy 2019-01-17T11:00:46Z DEBUG --------------------------------------------- 2019-01-17T11:00:46Z DEBUG Final value after applying updates 2019-01-17T11:00:46Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=services,cn=accounts,dc=local 2019-01-17T11:00:46Z DEBUG objectclass: 2019-01-17T11:00:46Z DEBUG top 2019-01-17T11:00:46Z DEBUG cosTemplate 2019-01-17T11:00:46Z DEBUG extensibleObject 2019-01-17T11:00:46Z DEBUG krbContainer 2019-01-17T11:00:46Z DEBUG krbPwdPolicyReference: 2019-01-17T11:00:46Z DEBUG cn=Default Service Password Policy,cn=services,cn=accounts,dc=local 2019-01-17T11:00:46Z DEBUG cosPriority: 2019-01-17T11:00:46Z DEBUG 10000000000 2019-01-17T11:00:46Z DEBUG cn: 2019-01-17T11:00:46Z DEBUG Default Password Policy 2019-01-17T11:00:46Z ERROR Parent DN of cn=Default Password Policy,cn=cosTemplates,cn=services,cn=accounts,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG New entry: cn=Default Password Policy,cn=services,cn=accounts,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=Default Password Policy,cn=services,cn=accounts,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG ldapsubentry 2019-01-17T11:00:47Z DEBUG cosSuperDefinition 2019-01-17T11:00:47Z DEBUG cosPointerDefinition 2019-01-17T11:00:47Z DEBUG cosTemplateDn: 2019-01-17T11:00:47Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=services,cn=accounts,dc=local 2019-01-17T11:00:47Z DEBUG description: 2019-01-17T11:00:47Z DEBUG Default Password Policy for Services 2019-01-17T11:00:47Z DEBUG cosAttribute: 2019-01-17T11:00:47Z DEBUG krbPwdPolicyReference default 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=Default Password Policy,cn=services,cn=accounts,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG ldapsubentry 2019-01-17T11:00:47Z DEBUG cosSuperDefinition 2019-01-17T11:00:47Z DEBUG cosPointerDefinition 2019-01-17T11:00:47Z DEBUG cosTemplateDn: 2019-01-17T11:00:47Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=services,cn=accounts,dc=local 2019-01-17T11:00:47Z DEBUG description: 2019-01-17T11:00:47Z DEBUG Default Password Policy for Services 2019-01-17T11:00:47Z DEBUG cosAttribute: 2019-01-17T11:00:47Z DEBUG krbPwdPolicyReference default 2019-01-17T11:00:47Z ERROR Parent DN of cn=Default Password Policy,cn=services,cn=accounts,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG New entry: cn=cosTemplates,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=cosTemplates,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:00:47Z DEBUG objectclass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsContainer 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG cosTemplates 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=cosTemplates,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:00:47Z DEBUG objectclass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsContainer 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG cosTemplates 2019-01-17T11:00:47Z ERROR Parent DN of cn=cosTemplates,cn=LOCAL,cn=kerberos,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG New entry: cn=Default Password Policy,cn=cosTemplates,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:00:47Z DEBUG objectclass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG cosTemplate 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG krbContainer 2019-01-17T11:00:47Z DEBUG krbPwdPolicyReference: 2019-01-17T11:00:47Z DEBUG cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:00:47Z DEBUG cosPriority: 2019-01-17T11:00:47Z DEBUG 10000000000 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Default Password Policy 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:00:47Z DEBUG objectclass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG cosTemplate 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG krbContainer 2019-01-17T11:00:47Z DEBUG krbPwdPolicyReference: 2019-01-17T11:00:47Z DEBUG cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:00:47Z DEBUG cosPriority: 2019-01-17T11:00:47Z DEBUG 10000000000 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Default Password Policy 2019-01-17T11:00:47Z ERROR Parent DN of cn=Default Password Policy,cn=cosTemplates,cn=LOCAL,cn=kerberos,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG New entry: cn=Default Password Policy,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=Default Password Policy,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG ldapsubentry 2019-01-17T11:00:47Z DEBUG cosSuperDefinition 2019-01-17T11:00:47Z DEBUG cosPointerDefinition 2019-01-17T11:00:47Z DEBUG cosTemplateDn: 2019-01-17T11:00:47Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:00:47Z DEBUG description: 2019-01-17T11:00:47Z DEBUG Default Password Policy for Kerberos Services 2019-01-17T11:00:47Z DEBUG cosAttribute: 2019-01-17T11:00:47Z DEBUG krbPwdPolicyReference default 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=Default Password Policy,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG ldapsubentry 2019-01-17T11:00:47Z DEBUG cosSuperDefinition 2019-01-17T11:00:47Z DEBUG cosPointerDefinition 2019-01-17T11:00:47Z DEBUG cosTemplateDn: 2019-01-17T11:00:47Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:00:47Z DEBUG description: 2019-01-17T11:00:47Z DEBUG Default Password Policy for Kerberos Services 2019-01-17T11:00:47Z DEBUG cosAttribute: 2019-01-17T11:00:47Z DEBUG krbPwdPolicyReference default 2019-01-17T11:00:47Z ERROR Parent DN of cn=Default Password Policy,cn=LOCAL,cn=kerberos,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG Parsing update file '/usr/share/ipa/updates/20-dna.update' 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=ipa-winsync,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=ipa-winsync,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ipa-winsync 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG ipawinsynchomedirattr: 2019-01-17T11:00:47Z DEBUG ipaHomesRootDir 2019-01-17T11:00:47Z DEBUG ipawinsyncnewuserocattr: 2019-01-17T11:00:47Z DEBUG ipauserobjectclasses 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libipa_winsync 2019-01-17T11:00:47Z DEBUG ipawinsyncuserflatten: 2019-01-17T11:00:47Z DEBUG true 2019-01-17T11:00:47Z DEBUG ipawinsyncdefaultgroupfilter: 2019-01-17T11:00:47Z DEBUG (gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames) 2019-01-17T11:00:47Z DEBUG ipawinsyncforcesync: 2019-01-17T11:00:47Z DEBUG true 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG FreeIPA/1.0 2019-01-17T11:00:47Z DEBUG ipawinsyncrealmattr: 2019-01-17T11:00:47Z DEBUG cn 2019-01-17T11:00:47Z DEBUG ipawinsyncacctdisable: 2019-01-17T11:00:47Z DEBUG both 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG ipa_winsync_plugin_init 2019-01-17T11:00:47Z DEBUG ipawinsyncnewentryfilter: 2019-01-17T11:00:47Z DEBUG (cn=ipaConfig) 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG FreeIPA project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:00:47Z DEBUG 60 2019-01-17T11:00:47Z DEBUG ipawinsyncdefaultgroupattr: 2019-01-17T11:00:47Z DEBUG ipaDefaultPrimaryGroup 2019-01-17T11:00:47Z DEBUG ipawinsyncrealmfilter: 2019-01-17T11:00:47Z DEBUG (objectclass=krbRealmContainer) 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG preoperation 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG ipa winsync plugin 2019-01-17T11:00:47Z DEBUG ipawinsyncloginshellattr: 2019-01-17T11:00:47Z DEBUG ipaDefaultLoginShell 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG ipa-winsync-plugin 2019-01-17T11:00:47Z DEBUG ipawinsyncuserattr: 2019-01-17T11:00:47Z DEBUG uidNumber -1 2019-01-17T11:00:47Z DEBUG gidNumber -1 2019-01-17T11:00:47Z DEBUG remove: 'uidNumber 999' from ipaWinSyncUserAttr, current value [u'uidNumber -1', u'gidNumber -1'] 2019-01-17T11:00:47Z DEBUG remove: 'uidNumber 999' not in ipaWinSyncUserAttr 2019-01-17T11:00:47Z DEBUG remove: 'gidNumber 999' from ipaWinSyncUserAttr, current value [u'uidNumber -1', u'gidNumber -1'] 2019-01-17T11:00:47Z DEBUG remove: 'gidNumber 999' not in ipaWinSyncUserAttr 2019-01-17T11:00:47Z DEBUG add: 'uidNumber -1' to ipaWinSyncUserAttr, current value [u'uidNumber -1', u'gidNumber -1'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'gidNumber -1', u'uidNumber -1'] 2019-01-17T11:00:47Z DEBUG add: 'gidNumber -1' to ipaWinSyncUserAttr, current value [u'gidNumber -1', u'uidNumber -1'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'uidNumber -1', u'gidNumber -1'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=ipa-winsync,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ipa-winsync 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG ipawinsynchomedirattr: 2019-01-17T11:00:47Z DEBUG ipaHomesRootDir 2019-01-17T11:00:47Z DEBUG ipawinsyncnewuserocattr: 2019-01-17T11:00:47Z DEBUG ipauserobjectclasses 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libipa_winsync 2019-01-17T11:00:47Z DEBUG ipawinsyncuserflatten: 2019-01-17T11:00:47Z DEBUG true 2019-01-17T11:00:47Z DEBUG ipawinsyncdefaultgroupfilter: 2019-01-17T11:00:47Z DEBUG (gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames) 2019-01-17T11:00:47Z DEBUG ipawinsyncforcesync: 2019-01-17T11:00:47Z DEBUG true 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG FreeIPA/1.0 2019-01-17T11:00:47Z DEBUG ipawinsyncrealmattr: 2019-01-17T11:00:47Z DEBUG cn 2019-01-17T11:00:47Z DEBUG ipawinsyncacctdisable: 2019-01-17T11:00:47Z DEBUG both 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG ipa_winsync_plugin_init 2019-01-17T11:00:47Z DEBUG ipawinsyncnewentryfilter: 2019-01-17T11:00:47Z DEBUG (cn=ipaConfig) 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG FreeIPA project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:00:47Z DEBUG 60 2019-01-17T11:00:47Z DEBUG ipawinsyncdefaultgroupattr: 2019-01-17T11:00:47Z DEBUG ipaDefaultPrimaryGroup 2019-01-17T11:00:47Z DEBUG ipawinsyncrealmfilter: 2019-01-17T11:00:47Z DEBUG (objectclass=krbRealmContainer) 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG preoperation 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG ipa winsync plugin 2019-01-17T11:00:47Z DEBUG ipawinsyncloginshellattr: 2019-01-17T11:00:47Z DEBUG ipaDefaultLoginShell 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG ipa-winsync-plugin 2019-01-17T11:00:47Z DEBUG ipawinsyncuserattr: 2019-01-17T11:00:47Z DEBUG uidNumber -1 2019-01-17T11:00:47Z DEBUG gidNumber -1 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Parsing update file '/usr/share/ipa/updates/20-enable_dirsrv_plugins.update' 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=7-bit check,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG NS7bitAttr 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG 7-bit check 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG NS7bitAttr_Init 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG Enforce 7-bit clean attribute values 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libattr-unique-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginarg0: 2019-01-17T11:00:47Z DEBUG uid 2019-01-17T11:00:47Z DEBUG nsslapd-pluginarg3: 2019-01-17T11:00:47Z DEBUG dc=local 2019-01-17T11:00:47Z DEBUG nsslapd-pluginarg2: 2019-01-17T11:00:47Z DEBUG , 2019-01-17T11:00:47Z DEBUG nsslapd-pluginarg1: 2019-01-17T11:00:47Z DEBUG mail 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG betxnpreoperation 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG replace: off not found, skipping 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG NS7bitAttr 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG 7-bit check 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG NS7bitAttr_Init 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG Enforce 7-bit clean attribute values 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libattr-unique-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginarg0: 2019-01-17T11:00:47Z DEBUG uid 2019-01-17T11:00:47Z DEBUG nsslapd-pluginarg3: 2019-01-17T11:00:47Z DEBUG dc=local 2019-01-17T11:00:47Z DEBUG nsslapd-pluginarg2: 2019-01-17T11:00:47Z DEBUG , 2019-01-17T11:00:47Z DEBUG nsslapd-pluginarg1: 2019-01-17T11:00:47Z DEBUG mail 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG betxnpreoperation 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=Account Usability Plugin,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=Account Usability Plugin,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG Account Usability Control 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Account Usability Plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG Account Usability Control plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libacctusability-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG preoperation 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG auc_init 2019-01-17T11:00:47Z DEBUG replace: off not found, skipping 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=Account Usability Plugin,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG Account Usability Control 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Account Usability Plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG Account Usability Control plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libacctusability-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG preoperation 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG auc_init 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=ACL Plugin,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=ACL Plugin,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG acl 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ACL Plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG acl access check plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libacl-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG accesscontrol 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG acl_init 2019-01-17T11:00:47Z DEBUG replace: off not found, skipping 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=ACL Plugin,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG acl 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ACL Plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG acl access check plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libacl-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG accesscontrol 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG acl_init 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=ACL preoperation,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=ACL preoperation,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG acl 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ACL preoperation 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG acl access check plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libacl-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG preoperation 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG acl_preopInit 2019-01-17T11:00:47Z DEBUG replace: off not found, skipping 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=ACL preoperation,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG acl 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ACL preoperation 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG acl access check plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libacl-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG preoperation 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG acl_preopInit 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=Auto Membership Plugin,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG Auto Membership 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Auto Membership Plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG Auto Membership plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libautomember-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginConfigArea: 2019-01-17T11:00:47Z DEBUG cn=automember,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG betxnpreoperation 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG automember_init 2019-01-17T11:00:47Z DEBUG replace: off not found, skipping 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG Auto Membership 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Auto Membership Plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG Auto Membership plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libautomember-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginConfigArea: 2019-01-17T11:00:47Z DEBUG cn=automember,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG betxnpreoperation 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG automember_init 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=Bitwise Plugin,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=Bitwise Plugin,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG bitwise 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Bitwise Plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG bitwise match plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libbitwise-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG matchingRule 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG bitwise_init 2019-01-17T11:00:47Z DEBUG replace: off not found, skipping 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=Bitwise Plugin,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG bitwise 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Bitwise Plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG bitwise match plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libbitwise-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG matchingRule 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG bitwise_init 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=chaining database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=chaining database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG chaining database 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG chaining database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG LDAP chaining backend database plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libchainingdb-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG chaining_back_init 2019-01-17T11:00:47Z DEBUG replace: off not found, skipping 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=chaining database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG chaining database 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG chaining database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG LDAP chaining backend database plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libchainingdb-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG chaining_back_init 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=Class of Service,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=Class of Service,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG cos 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Class of Service 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-named: 2019-01-17T11:00:47Z DEBUG State Change Plugin 2019-01-17T11:00:47Z DEBUG Views 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG class of service plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libcos-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG object 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG cos_init 2019-01-17T11:00:47Z DEBUG replace: off not found, skipping 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=Class of Service,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG cos 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Class of Service 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-named: 2019-01-17T11:00:47Z DEBUG State Change Plugin 2019-01-17T11:00:47Z DEBUG Views 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG class of service plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libcos-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG object 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG cos_init 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=deref,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=deref,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG Dereference 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG deref 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG Dereference plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libderef-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsContainer 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG preoperation 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG deref_init 2019-01-17T11:00:47Z DEBUG replace: off not found, skipping 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=deref,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG Dereference 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG deref 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG Dereference plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libderef-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsContainer 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG preoperation 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG deref_init 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=HTTP Client,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=HTTP Client,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG http-client 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG HTTP Client 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG HTTP Client plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libhttp-client-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG preoperation 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG http_client_init 2019-01-17T11:00:47Z DEBUG replace: off not found, skipping 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=HTTP Client,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG http-client 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG HTTP Client 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG HTTP Client plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libhttp-client-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG preoperation 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG http_client_init 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=Internationalization Plugin,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=Internationalization Plugin,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG orderingrule 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Internationalization Plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG internationalized ordering rule plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libcollation-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-pluginarg0: 2019-01-17T11:00:47Z DEBUG /etc/dirsrv/slapd-LOCAL/slapd-collations.conf 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG orderingRule_init 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG matchingRule 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG replace: off not found, skipping 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=Internationalization Plugin,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG orderingrule 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Internationalization Plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG internationalized ordering rule plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libcollation-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-pluginarg0: 2019-01-17T11:00:47Z DEBUG /etc/dirsrv/slapd-LOCAL/slapd-collations.conf 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG orderingRule_init 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG matchingRule 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=Linked Attributes,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=Linked Attributes,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG Linked Attributes 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Linked Attributes 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG Linked Attributes plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG liblinkedattrs-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsContainer 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG betxnpreoperation 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG linked_attrs_init 2019-01-17T11:00:47Z DEBUG replace: off not found, skipping 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=Linked Attributes,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG Linked Attributes 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Linked Attributes 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG Linked Attributes plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG liblinkedattrs-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsContainer 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG betxnpreoperation 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG linked_attrs_init 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=Managed Entries,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG Managed Entries 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Managed Entries 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG Managed Entries plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libmanagedentries-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsContainer 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginConfigArea: 2019-01-17T11:00:47Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG betxnpreoperation 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG mep_init 2019-01-17T11:00:47Z DEBUG replace: off not found, skipping 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG Managed Entries 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Managed Entries 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG Managed Entries plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libmanagedentries-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsContainer 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginConfigArea: 2019-01-17T11:00:47Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG betxnpreoperation 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG mep_init 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=Multimaster Replication Plugin,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=Multimaster Replication Plugin,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Multimaster Replication Plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG replication_multimaster_plugin_init 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-named: 2019-01-17T11:00:47Z DEBUG ldbm database 2019-01-17T11:00:47Z DEBUG AES 2019-01-17T11:00:47Z DEBUG Class of Service 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG Multi-master Replication Plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libreplication-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG replication-multimaster 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG object 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG replace: off not found, skipping 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=Multimaster Replication Plugin,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Multimaster Replication Plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG replication_multimaster_plugin_init 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-named: 2019-01-17T11:00:47Z DEBUG ldbm database 2019-01-17T11:00:47Z DEBUG AES 2019-01-17T11:00:47Z DEBUG Class of Service 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG Multi-master Replication Plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libreplication-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG replication-multimaster 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG object 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=Roles Plugin,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=Roles Plugin,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Roles Plugin 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-named: 2019-01-17T11:00:47Z DEBUG State Change Plugin 2019-01-17T11:00:47Z DEBUG Views 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG roles plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libroles-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG roles 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG roles_init 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG object 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG replace: off not found, skipping 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=Roles Plugin,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Roles Plugin 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-named: 2019-01-17T11:00:47Z DEBUG State Change Plugin 2019-01-17T11:00:47Z DEBUG Views 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG roles plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libroles-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG roles 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG roles_init 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG object 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=Schema Reload,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=Schema Reload,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG schemareload 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Schema Reload 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG task plugin to reload schema files 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libschemareload-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG object 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG schemareload_init 2019-01-17T11:00:47Z DEBUG replace: off not found, skipping 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=Schema Reload,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG schemareload 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Schema Reload 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG task plugin to reload schema files 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libschemareload-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG object 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG schemareload_init 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=State Change Plugin,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=State Change Plugin,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG statechange 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG State Change Plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG state change notification service plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libstatechange-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG betxnpostoperation 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG statechange_init 2019-01-17T11:00:47Z DEBUG replace: off not found, skipping 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=State Change Plugin,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG statechange 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG State Change Plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG state change notification service plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libstatechange-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG betxnpostoperation 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG statechange_init 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=Views,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=Views,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG views 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Views 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-named: 2019-01-17T11:00:47Z DEBUG State Change Plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG virtual directory information tree views plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libviews-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG object 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG views_init 2019-01-17T11:00:47Z DEBUG replace: off not found, skipping 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=Views,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG views 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Views 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-named: 2019-01-17T11:00:47Z DEBUG State Change Plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG virtual directory information tree views plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libviews-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG object 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG views_init 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=whoami,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=whoami,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG whoami-plugin 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG whoami 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG whoami extended operation plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libwhoami-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG extendedop 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG whoami_init 2019-01-17T11:00:47Z DEBUG replace: off not found, skipping 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=whoami,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG whoami-plugin 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG whoami 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG whoami extended operation plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libwhoami-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG extendedop 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG whoami_init 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Parsing update file '/usr/share/ipa/updates/20-host_nis_groups.update' 2019-01-17T11:00:47Z DEBUG New entry: cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG objectclass: 2019-01-17T11:00:47Z DEBUG mepTemplateEntry 2019-01-17T11:00:47Z DEBUG mepMappedAttr: 2019-01-17T11:00:47Z DEBUG cn: $cn 2019-01-17T11:00:47Z DEBUG memberHost: $dn 2019-01-17T11:00:47Z DEBUG description: ipaNetgroup $cn 2019-01-17T11:00:47Z DEBUG mepStaticAttr: 2019-01-17T11:00:47Z DEBUG ipaUniqueId: autogenerate 2019-01-17T11:00:47Z DEBUG objectclass: ipanisnetgroup 2019-01-17T11:00:47Z DEBUG objectclass: ipaobject 2019-01-17T11:00:47Z DEBUG nisDomainName: local 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG NGP HGP Template 2019-01-17T11:00:47Z DEBUG mepRDNAttr: 2019-01-17T11:00:47Z DEBUG cn 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG objectclass: 2019-01-17T11:00:47Z DEBUG mepTemplateEntry 2019-01-17T11:00:47Z DEBUG mepMappedAttr: 2019-01-17T11:00:47Z DEBUG cn: $cn 2019-01-17T11:00:47Z DEBUG memberHost: $dn 2019-01-17T11:00:47Z DEBUG description: ipaNetgroup $cn 2019-01-17T11:00:47Z DEBUG mepStaticAttr: 2019-01-17T11:00:47Z DEBUG ipaUniqueId: autogenerate 2019-01-17T11:00:47Z DEBUG objectclass: ipanisnetgroup 2019-01-17T11:00:47Z DEBUG objectclass: ipaobject 2019-01-17T11:00:47Z DEBUG nisDomainName: local 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG NGP HGP Template 2019-01-17T11:00:47Z DEBUG mepRDNAttr: 2019-01-17T11:00:47Z DEBUG cn 2019-01-17T11:00:47Z ERROR Parent DN of cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG New entry: cn=NGP Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=NGP Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG objectclass: 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG originScope: 2019-01-17T11:00:47Z DEBUG cn=hostgroups,cn=accounts,dc=local 2019-01-17T11:00:47Z DEBUG originFilter: 2019-01-17T11:00:47Z DEBUG objectclass=ipahostgroup 2019-01-17T11:00:47Z DEBUG managedTemplate: 2019-01-17T11:00:47Z DEBUG cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG managedBase: 2019-01-17T11:00:47Z DEBUG cn=ng,cn=alt,dc=local 2019-01-17T11:00:47Z DEBUG only: set cn to 'NGP Definition', current value [] 2019-01-17T11:00:47Z DEBUG only: updated value [u'NGP Definition'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=NGP Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG NGP Definition 2019-01-17T11:00:47Z DEBUG objectclass: 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG managedBase: 2019-01-17T11:00:47Z DEBUG cn=ng,cn=alt,dc=local 2019-01-17T11:00:47Z DEBUG originFilter: 2019-01-17T11:00:47Z DEBUG objectclass=ipahostgroup 2019-01-17T11:00:47Z DEBUG originScope: 2019-01-17T11:00:47Z DEBUG cn=hostgroups,cn=accounts,dc=local 2019-01-17T11:00:47Z DEBUG managedTemplate: 2019-01-17T11:00:47Z DEBUG cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:00:47Z ERROR Parent DN of cn=NGP Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG Parsing update file '/usr/share/ipa/updates/20-idoverride_index.update' 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=ipaOriginalUid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=ipaOriginalUid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ipaOriginalUid 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=ipaOriginalUid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ipaOriginalUid 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ipaAnchorUUID 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ipaAnchorUUID 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ipaAnchorUUID 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG remove: 'ipaOriginalUid' from cn, current value [u'ipaAnchorUUID'] 2019-01-17T11:00:47Z DEBUG remove: 'ipaOriginalUid' not in cn 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ipaAnchorUUID 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Parsing update file '/usr/share/ipa/updates/20-indices.update' 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=memberuid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=memberuid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG memberuid 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=memberuid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG memberuid 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=memberHost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=memberHost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG memberHost 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=memberHost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG memberHost 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=memberUser,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=memberUser,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG memberUser 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=memberUser,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG memberUser 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=member,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=member,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG member 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=member,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG member 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=uniquemember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=uniquemember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG uniquemember 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'sub'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'sub', current value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'sub'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=uniquemember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG uniquemember 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=owner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=owner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG owner 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'sub'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'sub', current value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'sub'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=owner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG owner 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=manager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=manager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG manager 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=manager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG manager 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=secretary,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=secretary,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG secretary 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=secretary,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG secretary 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=seeAlso,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=seeAlso,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG seeAlso 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'sub'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'sub', current value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'sub'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=seeAlso,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG seeAlso 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=memberOf,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=memberOf,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG memberOf 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=memberOf,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG memberOf 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=fqdn,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=fqdn,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG fqdn 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=fqdn,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG fqdn 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=macAddress,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=macAddress,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG macAddress 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=macAddress,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG macAddress 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=sourcehost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=sourcehost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG sourcehost 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=sourcehost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG sourcehost 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=memberservice,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=memberservice,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG memberservice 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=memberservice,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG memberservice 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=managedby,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=managedby,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG managedby 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=managedby,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG managedby 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=memberallowcmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=memberallowcmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG memberallowcmd 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=memberallowcmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG memberallowcmd 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=memberdenycmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=memberdenycmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG memberdenycmd 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=memberdenycmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG memberdenycmd 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=ipasudorunas,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=ipasudorunas,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ipasudorunas 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=ipasudorunas,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ipasudorunas 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=ipasudorunasgroup,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=ipasudorunasgroup,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ipasudorunasgroup 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=ipasudorunasgroup,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ipasudorunasgroup 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=automountkey,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=automountkey,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG automountkey 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=automountkey,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG automountkey 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=ipakrbprincipalalias,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=ipakrbprincipalalias,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ipakrbprincipalalias 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=ipakrbprincipalalias,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ipakrbprincipalalias 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=ipauniqueid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=ipauniqueid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ipauniqueid 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=ipauniqueid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ipauniqueid 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=ipatokenradiusconfiglink,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=ipatokenradiusconfiglink,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ipatokenradiusconfiglink 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=ipatokenradiusconfiglink,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ipatokenradiusconfiglink 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=ipaassignedidview,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=ipaassignedidview,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ipaassignedidview 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=ipaassignedidview,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ipaassignedidview 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=ipaallowedtarget,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=ipaallowedtarget,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ipaallowedtarget 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=ipaallowedtarget,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ipaallowedtarget 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=ipaMemberCa,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=ipaMemberCa,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ipaMemberCa 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=ipaMemberCa,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ipaMemberCa 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=ipaMemberCertProfile,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=ipaMemberCertProfile,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ipaMemberCertProfile 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=ipaMemberCertProfile,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ipaMemberCertProfile 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=userCertificate,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=userCertificate,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG userCertificate 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG only: set nsSystemIndex to 'false', current value [u'false'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'false'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=userCertificate,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG userCertificate 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ntUniqueId 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ntUniqueId 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ntUserDomainId 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ntUserDomainId 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=ipalocation,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=ipalocation,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ipalocation 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=ipalocation,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ipalocation 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=krbPrincipalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=krbPrincipalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG nsMatchingRule: 2019-01-17T11:00:47Z DEBUG caseIgnoreIA5Match 2019-01-17T11:00:47Z DEBUG caseExactIA5Match 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG krbPrincipalName 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG only: set nsMatchingRule to 'caseIgnoreIA5Match', current value [u'caseIgnoreIA5Match', u'caseExactIA5Match'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'caseIgnoreIA5Match'] 2019-01-17T11:00:47Z DEBUG only: set nsMatchingRule to 'caseExactIA5Match', current value [u'caseIgnoreIA5Match'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'caseIgnoreIA5Match', u'caseExactIA5Match'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'sub'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'sub', current value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'sub'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=krbPrincipalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG nsMatchingRule: 2019-01-17T11:00:47Z DEBUG caseIgnoreIA5Match 2019-01-17T11:00:47Z DEBUG caseExactIA5Match 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG krbPrincipalName 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=krbCanonicalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=krbCanonicalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG krbCanonicalName 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG only: set nsSystemIndex to 'false', current value [u'false'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'false'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'sub'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'sub', current value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'sub'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=krbCanonicalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG krbCanonicalName 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=serverhostname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=serverhostname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG serverhostname 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG only: set nsSystemIndex to 'false', current value [u'false'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'false'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'sub'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'sub', current value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'sub'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=serverhostname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG serverhostname 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=description,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=description,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsindex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG description 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=description,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsindex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG description 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=l,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=l,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsindex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG l 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=l,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsindex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG l 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=nsOsVersion,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=nsOsVersion,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsindex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG nsOsVersion 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=nsOsVersion,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsindex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG nsOsVersion 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=nsHardwarePlatform,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=nsHardwarePlatform,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsindex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG nsHardwarePlatform 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=nsHardwarePlatform,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsindex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG nsHardwarePlatform 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=nsHostLocation,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=nsHostLocation,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsindex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG nsHostLocation 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=nsHostLocation,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG sub 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsindex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG nsHostLocation 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Parsing update file '/usr/share/ipa/updates/20-ipaservers_hostgroup.update' 2019-01-17T11:00:47Z DEBUG New entry: cn=ipaservers,cn=hostgroups,cn=accounts,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG groupOfNames 2019-01-17T11:00:47Z DEBUG nestedGroup 2019-01-17T11:00:47Z DEBUG ipaobject 2019-01-17T11:00:47Z DEBUG ipahostgroup 2019-01-17T11:00:47Z DEBUG ipaUniqueID: 2019-01-17T11:00:47Z DEBUG autogenerate 2019-01-17T11:00:47Z DEBUG description: 2019-01-17T11:00:47Z DEBUG IPA server hosts 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ipaservers 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG groupOfNames 2019-01-17T11:00:47Z DEBUG nestedGroup 2019-01-17T11:00:47Z DEBUG ipaobject 2019-01-17T11:00:47Z DEBUG ipahostgroup 2019-01-17T11:00:47Z DEBUG ipaUniqueID: 2019-01-17T11:00:47Z DEBUG autogenerate 2019-01-17T11:00:47Z DEBUG description: 2019-01-17T11:00:47Z DEBUG IPA server hosts 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ipaservers 2019-01-17T11:00:47Z ERROR Parent DN of cn=ipaservers,cn=hostgroups,cn=accounts,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG New entry: cn=ipaservers,cn=hostgroups,cn=accounts,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=local 2019-01-17T11:00:47Z DEBUG add: 'fqdn=centos75.local,cn=computers,cn=accounts,dc=local' to member, current value [] 2019-01-17T11:00:47Z DEBUG add: updated value [u'fqdn=centos75.local,cn=computers,cn=accounts,dc=local'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=local 2019-01-17T11:00:47Z DEBUG member: 2019-01-17T11:00:47Z DEBUG fqdn=centos75.local,cn=computers,cn=accounts,dc=local 2019-01-17T11:00:47Z ERROR Parent DN of cn=ipaservers,cn=hostgroups,cn=accounts,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG Parsing update file '/usr/share/ipa/updates/20-nss_ldap.update' 2019-01-17T11:00:47Z DEBUG New entry: dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: dc=local 2019-01-17T11:00:47Z DEBUG add: 'domain' to objectClass, current value [] 2019-01-17T11:00:47Z DEBUG add: updated value [u'domain'] 2019-01-17T11:00:47Z DEBUG add: 'domainRelatedObject' to objectClass, current value [u'domain'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'domain', u'domainRelatedObject'] 2019-01-17T11:00:47Z DEBUG add: 'nisDomainObject' to objectClass, current value [u'domain', u'domainRelatedObject'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'domain', u'domainRelatedObject', u'nisDomainObject'] 2019-01-17T11:00:47Z DEBUG add: 'local' to associatedDomain, current value [] 2019-01-17T11:00:47Z DEBUG add: updated value [u'local'] 2019-01-17T11:00:47Z DEBUG add: 'local' to nisDomain, current value [] 2019-01-17T11:00:47Z DEBUG add: updated value [u'local'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG domain 2019-01-17T11:00:47Z DEBUG domainRelatedObject 2019-01-17T11:00:47Z DEBUG nisDomainObject 2019-01-17T11:00:47Z DEBUG associatedDomain: 2019-01-17T11:00:47Z DEBUG local 2019-01-17T11:00:47Z DEBUG nisDomain: 2019-01-17T11:00:47Z DEBUG local 2019-01-17T11:00:47Z DEBUG New entry: ou=profile,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: ou=profile,dc=local 2019-01-17T11:00:47Z DEBUG add: 'top' to objectClass, current value [] 2019-01-17T11:00:47Z DEBUG add: updated value [u'top'] 2019-01-17T11:00:47Z DEBUG add: 'organizationalUnit' to objectClass, current value [u'top'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'top', u'organizationalUnit'] 2019-01-17T11:00:47Z DEBUG add: 'profiles' to ou, current value [] 2019-01-17T11:00:47Z DEBUG add: updated value [u'profiles'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: ou=profile,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG organizationalUnit 2019-01-17T11:00:47Z DEBUG ou: 2019-01-17T11:00:47Z DEBUG profiles 2019-01-17T11:00:47Z DEBUG Unhandled LDAPError: OPERATIONS_ERROR: {'desc': 'Operations error'} 2019-01-17T11:00:47Z ERROR Add failure Operations error: 2019-01-17T11:00:47Z DEBUG New entry: cn=default,ou=profile,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=default,ou=profile,dc=local 2019-01-17T11:00:47Z DEBUG defaultServerList: 2019-01-17T11:00:47Z DEBUG centos75.local 2019-01-17T11:00:47Z DEBUG defaultSearchBase: 2019-01-17T11:00:47Z DEBUG dc=local 2019-01-17T11:00:47Z DEBUG ObjectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG DUAConfigProfile 2019-01-17T11:00:47Z DEBUG serviceSearchDescriptor: 2019-01-17T11:00:47Z DEBUG passwd:cn=users,cn=accounts,dc=local 2019-01-17T11:00:47Z DEBUG group:cn=groups,cn=compat,dc=local 2019-01-17T11:00:47Z DEBUG searchTimeLimit: 2019-01-17T11:00:47Z DEBUG 15 2019-01-17T11:00:47Z DEBUG followReferrals: 2019-01-17T11:00:47Z DEBUG TRUE 2019-01-17T11:00:47Z DEBUG objectClassMap: 2019-01-17T11:00:47Z DEBUG shadow:shadowAccount=posixAccount 2019-01-17T11:00:47Z DEBUG bindTimeLimit: 2019-01-17T11:00:47Z DEBUG 5 2019-01-17T11:00:47Z DEBUG authenticationMethod: 2019-01-17T11:00:47Z DEBUG none 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG default 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=default,ou=profile,dc=local 2019-01-17T11:00:47Z DEBUG defaultServerList: 2019-01-17T11:00:47Z DEBUG centos75.local 2019-01-17T11:00:47Z DEBUG defaultSearchBase: 2019-01-17T11:00:47Z DEBUG dc=local 2019-01-17T11:00:47Z DEBUG ObjectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG DUAConfigProfile 2019-01-17T11:00:47Z DEBUG serviceSearchDescriptor: 2019-01-17T11:00:47Z DEBUG passwd:cn=users,cn=accounts,dc=local 2019-01-17T11:00:47Z DEBUG group:cn=groups,cn=compat,dc=local 2019-01-17T11:00:47Z DEBUG searchTimeLimit: 2019-01-17T11:00:47Z DEBUG 15 2019-01-17T11:00:47Z DEBUG followReferrals: 2019-01-17T11:00:47Z DEBUG TRUE 2019-01-17T11:00:47Z DEBUG objectClassMap: 2019-01-17T11:00:47Z DEBUG shadow:shadowAccount=posixAccount 2019-01-17T11:00:47Z DEBUG bindTimeLimit: 2019-01-17T11:00:47Z DEBUG 5 2019-01-17T11:00:47Z DEBUG authenticationMethod: 2019-01-17T11:00:47Z DEBUG none 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG default 2019-01-17T11:00:47Z ERROR Parent DN of cn=default,ou=profile,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG Parsing update file '/usr/share/ipa/updates/20-replication.update' 2019-01-17T11:00:47Z DEBUG New entry: cn=replication,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=replication,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG objectclass: 2019-01-17T11:00:47Z DEBUG nsDS5Replica 2019-01-17T11:00:47Z DEBUG nsDS5ReplicaId: 2019-01-17T11:00:47Z DEBUG 3 2019-01-17T11:00:47Z DEBUG nsDS5ReplicaRoot: 2019-01-17T11:00:47Z DEBUG dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=replication,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG objectclass: 2019-01-17T11:00:47Z DEBUG nsDS5Replica 2019-01-17T11:00:47Z DEBUG nsDS5ReplicaId: 2019-01-17T11:00:47Z DEBUG 3 2019-01-17T11:00:47Z DEBUG nsDS5ReplicaRoot: 2019-01-17T11:00:47Z DEBUG dc=local 2019-01-17T11:00:47Z ERROR Parent DN of cn=replication,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG New entry: cn=replication managers,cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=replication managers,cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG objectclass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG groupofnames 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG replication managers 2019-01-17T11:00:47Z DEBUG add: 'krbprincipalname=ldap/centos75.local@LOCAL,cn=services,cn=accounts,dc=local' to member, current value [] 2019-01-17T11:00:47Z DEBUG add: updated value [u'krbprincipalname=ldap/centos75.local@LOCAL,cn=services,cn=accounts,dc=local'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=replication managers,cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG objectclass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG groupofnames 2019-01-17T11:00:47Z DEBUG member: 2019-01-17T11:00:47Z DEBUG krbprincipalname=ldap/centos75.local@LOCAL,cn=services,cn=accounts,dc=local 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG replication managers 2019-01-17T11:00:47Z ERROR Parent DN of cn=replication managers,cn=sysaccounts,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG New entry: cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG objectclass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsContainer 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG topology 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG objectclass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsContainer 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG topology 2019-01-17T11:00:47Z ERROR Parent DN of cn=topology,cn=ipa,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG New entry: cn=domain,cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=domain,cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG objectclass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG iparepltopoconf 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG domain 2019-01-17T11:00:47Z DEBUG ipaReplTopoConfRoot: 2019-01-17T11:00:47Z DEBUG dc=local 2019-01-17T11:00:47Z DEBUG add: '(objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount' to nsDS5ReplicatedAttributeList, current value [] 2019-01-17T11:00:47Z DEBUG add: updated value [u'(objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount'] 2019-01-17T11:00:47Z DEBUG add: '(objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount' to nsDS5ReplicatedAttributeListTotal, current value [] 2019-01-17T11:00:47Z DEBUG add: updated value [u'(objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount'] 2019-01-17T11:00:47Z DEBUG add: 'modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp' to nsds5ReplicaStripAttrs, current value [] 2019-01-17T11:00:47Z DEBUG add: updated value [u'modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=domain,cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG nsds5ReplicaStripAttrs: 2019-01-17T11:00:47Z DEBUG modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp 2019-01-17T11:00:47Z DEBUG ipaReplTopoConfRoot: 2019-01-17T11:00:47Z DEBUG dc=local 2019-01-17T11:00:47Z DEBUG objectclass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG iparepltopoconf 2019-01-17T11:00:47Z DEBUG nsDS5ReplicatedAttributeListTotal: 2019-01-17T11:00:47Z DEBUG (objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount 2019-01-17T11:00:47Z DEBUG nsDS5ReplicatedAttributeList: 2019-01-17T11:00:47Z DEBUG (objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG domain 2019-01-17T11:00:47Z ERROR Parent DN of cn=domain,cn=topology,cn=ipa,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG Deleting entry cn=realm,cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG cn=realm,cn=topology,cn=ipa,cn=etc,dc=local did not exist:no such entry 2019-01-17T11:00:47Z DEBUG New entry: cn=centos75.local,cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=centos75.local,cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG add: 'ipaReplTopoManagedServer' to objectclass, current value [] 2019-01-17T11:00:47Z DEBUG add: updated value [u'ipaReplTopoManagedServer'] 2019-01-17T11:00:47Z DEBUG add: 'dc=local' to ipaReplTopoManagedSuffix, current value [] 2019-01-17T11:00:47Z DEBUG add: updated value [u'dc=local'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=centos75.local,cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG objectclass: 2019-01-17T11:00:47Z DEBUG ipaReplTopoManagedServer 2019-01-17T11:00:47Z DEBUG ipaReplTopoManagedSuffix: 2019-01-17T11:00:47Z DEBUG dc=local 2019-01-17T11:00:47Z ERROR Parent DN of cn=centos75.local,cn=masters,cn=ipa,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=IPA Topology Configuration,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=IPA Topology Configuration,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG ipa-topology-plugin 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG IPA Topology Configuration 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG ipa_topo_init 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-named: 2019-01-17T11:00:47Z DEBUG ldbm database 2019-01-17T11:00:47Z DEBUG Multimaster Replication Plugin 2019-01-17T11:00:47Z DEBUG nsslapd-topo-plugin-shared-replica-root: 2019-01-17T11:00:47Z DEBUG dc=local 2019-01-17T11:00:47Z DEBUG o=ipaca 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.0 2019-01-17T11:00:47Z DEBUG nsslapd-topo-plugin-shared-config-base: 2019-01-17T11:00:47Z DEBUG cn=ipa,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG ipa-topology-plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libtopology 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG object 2019-01-17T11:00:47Z DEBUG nsslapd-topo-plugin-shared-binddngroup: 2019-01-17T11:00:47Z DEBUG cn=replication managers,cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG nsslapd-topo-plugin-startup-delay: 2019-01-17T11:00:47Z DEBUG 20 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG freeipa 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=IPA Topology Configuration,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG ipa-topology-plugin 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG IPA Topology Configuration 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG ipa_topo_init 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-named: 2019-01-17T11:00:47Z DEBUG ldbm database 2019-01-17T11:00:47Z DEBUG Multimaster Replication Plugin 2019-01-17T11:00:47Z DEBUG nsslapd-topo-plugin-shared-replica-root: 2019-01-17T11:00:47Z DEBUG dc=local 2019-01-17T11:00:47Z DEBUG o=ipaca 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.0 2019-01-17T11:00:47Z DEBUG nsslapd-topo-plugin-shared-config-base: 2019-01-17T11:00:47Z DEBUG cn=ipa,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG ipa-topology-plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libtopology 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG object 2019-01-17T11:00:47Z DEBUG nsslapd-topo-plugin-shared-binddngroup: 2019-01-17T11:00:47Z DEBUG cn=replication managers,cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG nsslapd-topo-plugin-startup-delay: 2019-01-17T11:00:47Z DEBUG 20 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG freeipa 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG New entry: cn=changelog5,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=changelog5,cn=config 2019-01-17T11:00:47Z DEBUG addifnew: '7d' to nsslapd-changelogmaxage, current value [] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=changelog5,cn=config 2019-01-17T11:00:47Z DEBUG Parsing update file '/usr/share/ipa/updates/20-sslciphers.update' 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=encryption,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=encryption,cn=config 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG encryption 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsEncryptionConfig 2019-01-17T11:00:47Z DEBUG sslVersionMin: 2019-01-17T11:00:47Z DEBUG TLS1.0 2019-01-17T11:00:47Z DEBUG nsSSLSupportedCiphers: 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384::AES::SHA384::256 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_ECDSA_WITH_RC4_128_SHA::RC4::SHA1::128 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384::AES::SHA384::256 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2019-01-17T11:00:47Z DEBUG TLS_DHE_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2019-01-17T11:00:47Z DEBUG TLS_DHE_DSS_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2019-01-17T11:00:47Z DEBUG TLS_DHE_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2019-01-17T11:00:47Z DEBUG TLS_DHE_DSS_WITH_AES_256_CBC_SHA::AES::SHA1::256 2019-01-17T11:00:47Z DEBUG TLS_DHE_RSA_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2019-01-17T11:00:47Z DEBUG TLS_DHE_DSS_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2019-01-17T11:00:47Z DEBUG TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2019-01-17T11:00:47Z DEBUG TLS_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2019-01-17T11:00:47Z DEBUG TLS_DHE_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2019-01-17T11:00:47Z DEBUG TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2019-01-17T11:00:47Z DEBUG TLS_DHE_DSS_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2019-01-17T11:00:47Z DEBUG TLS_DHE_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2019-01-17T11:00:47Z DEBUG TLS_DHE_DSS_WITH_AES_128_CBC_SHA::AES::SHA1::128 2019-01-17T11:00:47Z DEBUG TLS_DHE_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2019-01-17T11:00:47Z DEBUG TLS_DHE_DSS_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2019-01-17T11:00:47Z DEBUG TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2019-01-17T11:00:47Z DEBUG TLS_DHE_DSS_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2019-01-17T11:00:47Z DEBUG TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2019-01-17T11:00:47Z DEBUG TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2019-01-17T11:00:47Z DEBUG TLS_DHE_DSS_WITH_RC4_128_SHA::RC4::SHA1::128 2019-01-17T11:00:47Z DEBUG TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2019-01-17T11:00:47Z DEBUG TLS_ECDH_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2019-01-17T11:00:47Z DEBUG TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2019-01-17T11:00:47Z DEBUG TLS_ECDH_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2019-01-17T11:00:47Z DEBUG TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2019-01-17T11:00:47Z DEBUG TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2019-01-17T11:00:47Z DEBUG TLS_ECDH_ECDSA_WITH_RC4_128_SHA::RC4::SHA1::128 2019-01-17T11:00:47Z DEBUG TLS_ECDH_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2019-01-17T11:00:47Z DEBUG TLS_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2019-01-17T11:00:47Z DEBUG TLS_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2019-01-17T11:00:47Z DEBUG TLS_RSA_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2019-01-17T11:00:47Z DEBUG TLS_RSA_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2019-01-17T11:00:47Z DEBUG TLS_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2019-01-17T11:00:47Z DEBUG TLS_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2019-01-17T11:00:47Z DEBUG TLS_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2019-01-17T11:00:47Z DEBUG TLS_RSA_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2019-01-17T11:00:47Z DEBUG TLS_RSA_WITH_SEED_CBC_SHA::SEED::SHA1::128 2019-01-17T11:00:47Z DEBUG TLS_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2019-01-17T11:00:47Z DEBUG TLS_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2019-01-17T11:00:47Z DEBUG TLS_RSA_WITH_RC4_128_MD5::RC4::MD5::128 2019-01-17T11:00:47Z DEBUG TLS_DHE_RSA_WITH_DES_CBC_SHA::DES::SHA1::64 2019-01-17T11:00:47Z DEBUG TLS_DHE_DSS_WITH_DES_CBC_SHA::DES::SHA1::64 2019-01-17T11:00:47Z DEBUG TLS_RSA_WITH_DES_CBC_SHA::DES::SHA1::64 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_ECDSA_WITH_NULL_SHA::NULL::SHA1::0 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_RSA_WITH_NULL_SHA::NULL::SHA1::0 2019-01-17T11:00:47Z DEBUG TLS_ECDH_RSA_WITH_NULL_SHA::NULL::SHA1::0 2019-01-17T11:00:47Z DEBUG TLS_ECDH_ECDSA_WITH_NULL_SHA::NULL::SHA1::0 2019-01-17T11:00:47Z DEBUG TLS_RSA_WITH_NULL_SHA::NULL::SHA1::0 2019-01-17T11:00:47Z DEBUG TLS_RSA_WITH_NULL_SHA256::NULL::SHA256::0 2019-01-17T11:00:47Z DEBUG TLS_RSA_WITH_NULL_MD5::NULL::MD5::0 2019-01-17T11:00:47Z DEBUG TLS_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2019-01-17T11:00:47Z DEBUG TLS_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2019-01-17T11:00:47Z DEBUG TLS_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2019-01-17T11:00:47Z DEBUG nsSSLClientAuth: 2019-01-17T11:00:47Z DEBUG allowed 2019-01-17T11:00:47Z DEBUG nsSSLSessionTimeout: 2019-01-17T11:00:47Z DEBUG 0 2019-01-17T11:00:47Z DEBUG allowWeakCipher: 2019-01-17T11:00:47Z DEBUG off 2019-01-17T11:00:47Z DEBUG CACertExtractFile: 2019-01-17T11:00:47Z DEBUG /etc/dirsrv/slapd-LOCAL/LOCAL20IPA20CA.pem 2019-01-17T11:00:47Z DEBUG nsSSL3Ciphers: 2019-01-17T11:00:47Z DEBUG default 2019-01-17T11:00:47Z DEBUG only: set nsSSL3Ciphers to 'default', current value [u'default'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'default'] 2019-01-17T11:00:47Z DEBUG addifnew: 'off' to allowWeakCipher, current value [u'off'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=encryption,cn=config 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG encryption 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsEncryptionConfig 2019-01-17T11:00:47Z DEBUG sslVersionMin: 2019-01-17T11:00:47Z DEBUG TLS1.0 2019-01-17T11:00:47Z DEBUG nsSSLSupportedCiphers: 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384::AES::SHA384::256 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_ECDSA_WITH_RC4_128_SHA::RC4::SHA1::128 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384::AES::SHA384::256 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2019-01-17T11:00:47Z DEBUG TLS_DHE_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2019-01-17T11:00:47Z DEBUG TLS_DHE_DSS_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2019-01-17T11:00:47Z DEBUG TLS_DHE_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2019-01-17T11:00:47Z DEBUG TLS_DHE_DSS_WITH_AES_256_CBC_SHA::AES::SHA1::256 2019-01-17T11:00:47Z DEBUG TLS_DHE_RSA_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2019-01-17T11:00:47Z DEBUG TLS_DHE_DSS_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2019-01-17T11:00:47Z DEBUG TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2019-01-17T11:00:47Z DEBUG TLS_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2019-01-17T11:00:47Z DEBUG TLS_DHE_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2019-01-17T11:00:47Z DEBUG TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2019-01-17T11:00:47Z DEBUG TLS_DHE_DSS_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2019-01-17T11:00:47Z DEBUG TLS_DHE_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2019-01-17T11:00:47Z DEBUG TLS_DHE_DSS_WITH_AES_128_CBC_SHA::AES::SHA1::128 2019-01-17T11:00:47Z DEBUG TLS_DHE_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2019-01-17T11:00:47Z DEBUG TLS_DHE_DSS_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2019-01-17T11:00:47Z DEBUG TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2019-01-17T11:00:47Z DEBUG TLS_DHE_DSS_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2019-01-17T11:00:47Z DEBUG TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2019-01-17T11:00:47Z DEBUG TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2019-01-17T11:00:47Z DEBUG TLS_DHE_DSS_WITH_RC4_128_SHA::RC4::SHA1::128 2019-01-17T11:00:47Z DEBUG TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2019-01-17T11:00:47Z DEBUG TLS_ECDH_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2019-01-17T11:00:47Z DEBUG TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2019-01-17T11:00:47Z DEBUG TLS_ECDH_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2019-01-17T11:00:47Z DEBUG TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2019-01-17T11:00:47Z DEBUG TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2019-01-17T11:00:47Z DEBUG TLS_ECDH_ECDSA_WITH_RC4_128_SHA::RC4::SHA1::128 2019-01-17T11:00:47Z DEBUG TLS_ECDH_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2019-01-17T11:00:47Z DEBUG TLS_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2019-01-17T11:00:47Z DEBUG TLS_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2019-01-17T11:00:47Z DEBUG TLS_RSA_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2019-01-17T11:00:47Z DEBUG TLS_RSA_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2019-01-17T11:00:47Z DEBUG TLS_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2019-01-17T11:00:47Z DEBUG TLS_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2019-01-17T11:00:47Z DEBUG TLS_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2019-01-17T11:00:47Z DEBUG TLS_RSA_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2019-01-17T11:00:47Z DEBUG TLS_RSA_WITH_SEED_CBC_SHA::SEED::SHA1::128 2019-01-17T11:00:47Z DEBUG TLS_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2019-01-17T11:00:47Z DEBUG TLS_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2019-01-17T11:00:47Z DEBUG TLS_RSA_WITH_RC4_128_MD5::RC4::MD5::128 2019-01-17T11:00:47Z DEBUG TLS_DHE_RSA_WITH_DES_CBC_SHA::DES::SHA1::64 2019-01-17T11:00:47Z DEBUG TLS_DHE_DSS_WITH_DES_CBC_SHA::DES::SHA1::64 2019-01-17T11:00:47Z DEBUG TLS_RSA_WITH_DES_CBC_SHA::DES::SHA1::64 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_ECDSA_WITH_NULL_SHA::NULL::SHA1::0 2019-01-17T11:00:47Z DEBUG TLS_ECDHE_RSA_WITH_NULL_SHA::NULL::SHA1::0 2019-01-17T11:00:47Z DEBUG TLS_ECDH_RSA_WITH_NULL_SHA::NULL::SHA1::0 2019-01-17T11:00:47Z DEBUG TLS_ECDH_ECDSA_WITH_NULL_SHA::NULL::SHA1::0 2019-01-17T11:00:47Z DEBUG TLS_RSA_WITH_NULL_SHA::NULL::SHA1::0 2019-01-17T11:00:47Z DEBUG TLS_RSA_WITH_NULL_SHA256::NULL::SHA256::0 2019-01-17T11:00:47Z DEBUG TLS_RSA_WITH_NULL_MD5::NULL::MD5::0 2019-01-17T11:00:47Z DEBUG TLS_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2019-01-17T11:00:47Z DEBUG TLS_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2019-01-17T11:00:47Z DEBUG TLS_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2019-01-17T11:00:47Z DEBUG nsSSLClientAuth: 2019-01-17T11:00:47Z DEBUG allowed 2019-01-17T11:00:47Z DEBUG nsSSLSessionTimeout: 2019-01-17T11:00:47Z DEBUG 0 2019-01-17T11:00:47Z DEBUG allowWeakCipher: 2019-01-17T11:00:47Z DEBUG off 2019-01-17T11:00:47Z DEBUG CACertExtractFile: 2019-01-17T11:00:47Z DEBUG /etc/dirsrv/slapd-LOCAL/LOCAL20IPA20CA.pem 2019-01-17T11:00:47Z DEBUG nsSSL3Ciphers: 2019-01-17T11:00:47Z DEBUG default 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Parsing update file '/usr/share/ipa/updates/20-syncrepl.update' 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=Retro Changelog Plugin,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=Retro Changelog Plugin,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-attribute: 2019-01-17T11:00:47Z DEBUG nsuniqueid:targetUniqueId 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Retro Changelog Plugin 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-named: 2019-01-17T11:00:47Z DEBUG Class of Service 2019-01-17T11:00:47Z DEBUG nsslapd-changelogmaxage: 2019-01-17T11:00:47Z DEBUG 2d 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG Retrocl Plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libretrocl-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-include-suffix: 2019-01-17T11:00:47Z DEBUG cn=dns,dc=local 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG retrocl 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG retrocl_plugin_init 2019-01-17T11:00:47Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:00:47Z DEBUG 25 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG object 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG only: set nsslapd-pluginEnabled to 'on', current value [u'on'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'on'] 2019-01-17T11:00:47Z DEBUG add: 'nsuniqueid:targetUniqueId' to nsslapd-attribute, current value [u'nsuniqueid:targetUniqueId'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'nsuniqueid:targetUniqueId'] 2019-01-17T11:00:47Z DEBUG add: '2d' to nsslapd-changelogmaxage, current value [u'2d'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'2d'] 2019-01-17T11:00:47Z DEBUG add: 'cn=dns,dc=local' to nsslapd-include-suffix, current value [u'cn=dns,dc=local'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'cn=dns,dc=local'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=Retro Changelog Plugin,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-attribute: 2019-01-17T11:00:47Z DEBUG nsuniqueid:targetUniqueId 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Retro Changelog Plugin 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-named: 2019-01-17T11:00:47Z DEBUG Class of Service 2019-01-17T11:00:47Z DEBUG nsslapd-changelogmaxage: 2019-01-17T11:00:47Z DEBUG 2d 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG Retrocl Plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libretrocl-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-include-suffix: 2019-01-17T11:00:47Z DEBUG cn=dns,dc=local 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG retrocl 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG retrocl_plugin_init 2019-01-17T11:00:47Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:00:47Z DEBUG 25 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG object 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=MemberOf Plugin,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=MemberOf Plugin,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG memberof 2019-01-17T11:00:47Z DEBUG memberofgroupattr: 2019-01-17T11:00:47Z DEBUG member 2019-01-17T11:00:47Z DEBUG memberUser 2019-01-17T11:00:47Z DEBUG memberHost 2019-01-17T11:00:47Z DEBUG memberofentryscope: 2019-01-17T11:00:47Z DEBUG dc=local 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG MemberOf Plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG memberof plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libmemberof-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG memberofattr: 2019-01-17T11:00:47Z DEBUG memberOf 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG betxnpostoperation 2019-01-17T11:00:47Z DEBUG memberofentryscopeexcludesubtree: 2019-01-17T11:00:47Z DEBUG cn=compat,dc=local 2019-01-17T11:00:47Z DEBUG cn=provisioning,dc=local 2019-01-17T11:00:47Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG memberof_postop_init 2019-01-17T11:00:47Z DEBUG add: 'dc=local' to memberofentryscope, current value [u'dc=local'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'dc=local'] 2019-01-17T11:00:47Z DEBUG add: 'cn=compat,dc=local' to memberofentryscopeexcludesubtree, current value [u'cn=compat,dc=local', u'cn=provisioning,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'cn=provisioning,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local', u'cn=compat,dc=local'] 2019-01-17T11:00:47Z DEBUG add: 'cn=provisioning,dc=local' to memberofentryscopeexcludesubtree, current value [u'cn=provisioning,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local', u'cn=compat,dc=local'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'cn=topology,cn=ipa,cn=etc,dc=local', u'cn=compat,dc=local', u'cn=provisioning,dc=local'] 2019-01-17T11:00:47Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=local' to memberofentryscopeexcludesubtree, current value [u'cn=topology,cn=ipa,cn=etc,dc=local', u'cn=compat,dc=local', u'cn=provisioning,dc=local'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'cn=compat,dc=local', u'cn=provisioning,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=MemberOf Plugin,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG memberof 2019-01-17T11:00:47Z DEBUG memberofgroupattr: 2019-01-17T11:00:47Z DEBUG member 2019-01-17T11:00:47Z DEBUG memberUser 2019-01-17T11:00:47Z DEBUG memberHost 2019-01-17T11:00:47Z DEBUG memberofentryscope: 2019-01-17T11:00:47Z DEBUG dc=local 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG MemberOf Plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG memberof plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libmemberof-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG memberofattr: 2019-01-17T11:00:47Z DEBUG memberOf 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG betxnpostoperation 2019-01-17T11:00:47Z DEBUG memberofentryscopeexcludesubtree: 2019-01-17T11:00:47Z DEBUG cn=compat,dc=local 2019-01-17T11:00:47Z DEBUG cn=provisioning,dc=local 2019-01-17T11:00:47Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG memberof_postop_init 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=referential integrity postoperation,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG referint 2019-01-17T11:00:47Z DEBUG nsslapd-plugincontainerscope: 2019-01-17T11:00:47Z DEBUG dc=local 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG referential integrity postoperation 2019-01-17T11:00:47Z DEBUG referint-update-delay: 2019-01-17T11:00:47Z DEBUG 0 2019-01-17T11:00:47Z DEBUG nsslapd-pluginexcludeentryscope: 2019-01-17T11:00:47Z DEBUG cn=provisioning,dc=local 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG referential integrity plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginentryscope: 2019-01-17T11:00:47Z DEBUG dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libreferint-plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:00:47Z DEBUG 40 2019-01-17T11:00:47Z DEBUG referint-logfile: 2019-01-17T11:00:47Z DEBUG /var/log/dirsrv/slapd-LOCAL/referint 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG betxnpostoperation 2019-01-17T11:00:47Z DEBUG referint-membership-attr: 2019-01-17T11:00:47Z DEBUG member 2019-01-17T11:00:47Z DEBUG uniquemember 2019-01-17T11:00:47Z DEBUG owner 2019-01-17T11:00:47Z DEBUG seeAlso 2019-01-17T11:00:47Z DEBUG manager 2019-01-17T11:00:47Z DEBUG secretary 2019-01-17T11:00:47Z DEBUG memberuser 2019-01-17T11:00:47Z DEBUG memberhost 2019-01-17T11:00:47Z DEBUG sourcehost 2019-01-17T11:00:47Z DEBUG memberservice 2019-01-17T11:00:47Z DEBUG managedby 2019-01-17T11:00:47Z DEBUG memberallowcmd 2019-01-17T11:00:47Z DEBUG memberdenycmd 2019-01-17T11:00:47Z DEBUG ipasudorunas 2019-01-17T11:00:47Z DEBUG ipasudorunasgroup 2019-01-17T11:00:47Z DEBUG ipatokenradiusconfiglink 2019-01-17T11:00:47Z DEBUG ipaassignedidview 2019-01-17T11:00:47Z DEBUG ipaallowedtarget 2019-01-17T11:00:47Z DEBUG ipamemberca 2019-01-17T11:00:47Z DEBUG ipamembercertprofile 2019-01-17T11:00:47Z DEBUG ipalocation 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG referint_postop_init 2019-01-17T11:00:47Z DEBUG add: 'dc=local' to nsslapd-plugincontainerscope, current value [u'dc=local'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'dc=local'] 2019-01-17T11:00:47Z DEBUG add: 'dc=local' to nsslapd-pluginentryscope, current value [u'dc=local'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'dc=local'] 2019-01-17T11:00:47Z DEBUG add: 'cn=provisioning,dc=local' to nsslapd-pluginExcludeEntryScope, current value [u'cn=provisioning,dc=local'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'cn=provisioning,dc=local'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG referint 2019-01-17T11:00:47Z DEBUG nsslapd-plugincontainerscope: 2019-01-17T11:00:47Z DEBUG dc=local 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG referential integrity postoperation 2019-01-17T11:00:47Z DEBUG referint-update-delay: 2019-01-17T11:00:47Z DEBUG 0 2019-01-17T11:00:47Z DEBUG nsslapd-pluginexcludeentryscope: 2019-01-17T11:00:47Z DEBUG cn=provisioning,dc=local 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG referential integrity plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginentryscope: 2019-01-17T11:00:47Z DEBUG dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libreferint-plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:00:47Z DEBUG 40 2019-01-17T11:00:47Z DEBUG referint-logfile: 2019-01-17T11:00:47Z DEBUG /var/log/dirsrv/slapd-LOCAL/referint 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG betxnpostoperation 2019-01-17T11:00:47Z DEBUG referint-membership-attr: 2019-01-17T11:00:47Z DEBUG member 2019-01-17T11:00:47Z DEBUG uniquemember 2019-01-17T11:00:47Z DEBUG owner 2019-01-17T11:00:47Z DEBUG seeAlso 2019-01-17T11:00:47Z DEBUG manager 2019-01-17T11:00:47Z DEBUG secretary 2019-01-17T11:00:47Z DEBUG memberuser 2019-01-17T11:00:47Z DEBUG memberhost 2019-01-17T11:00:47Z DEBUG sourcehost 2019-01-17T11:00:47Z DEBUG memberservice 2019-01-17T11:00:47Z DEBUG managedby 2019-01-17T11:00:47Z DEBUG memberallowcmd 2019-01-17T11:00:47Z DEBUG memberdenycmd 2019-01-17T11:00:47Z DEBUG ipasudorunas 2019-01-17T11:00:47Z DEBUG ipasudorunasgroup 2019-01-17T11:00:47Z DEBUG ipatokenradiusconfiglink 2019-01-17T11:00:47Z DEBUG ipaassignedidview 2019-01-17T11:00:47Z DEBUG ipaallowedtarget 2019-01-17T11:00:47Z DEBUG ipamemberca 2019-01-17T11:00:47Z DEBUG ipamembercertprofile 2019-01-17T11:00:47Z DEBUG ipalocation 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG referint_postop_init 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=Content Synchronization,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=Content Synchronization,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Content Synchronization 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-named: 2019-01-17T11:00:47Z DEBUG Retro Changelog Plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG Context Synchronization (RFC4533) plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libcontentsync-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG content-sync-plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG sync_init 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG object 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG only: set nsslapd-pluginEnabled to 'on', current value [u'on'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'on'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=Content Synchronization,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Content Synchronization 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-named: 2019-01-17T11:00:47Z DEBUG Retro Changelog Plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG Context Synchronization (RFC4533) plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libcontentsync-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG content-sync-plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG sync_init 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG object 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=IPA Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=IPA Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG IPA Unique IDs 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG ipauuidmagicregen: 2019-01-17T11:00:47Z DEBUG autogenerate 2019-01-17T11:00:47Z DEBUG ipauuidfilter: 2019-01-17T11:00:47Z DEBUG (|(objectclass=ipaObject)(objectclass=ipaAssociation)) 2019-01-17T11:00:47Z DEBUG ipauuidenforce: 2019-01-17T11:00:47Z DEBUG TRUE 2019-01-17T11:00:47Z DEBUG ipauuidexcludesubtree: 2019-01-17T11:00:47Z DEBUG cn=provisioning,dc=local 2019-01-17T11:00:47Z DEBUG ipauuidattr: 2019-01-17T11:00:47Z DEBUG ipaUniqueID 2019-01-17T11:00:47Z DEBUG ipauuidscope: 2019-01-17T11:00:47Z DEBUG dc=local 2019-01-17T11:00:47Z DEBUG add: 'cn=provisioning,dc=local' to ipaUuidExcludeSubtree, current value [u'cn=provisioning,dc=local'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'cn=provisioning,dc=local'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=IPA Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG IPA Unique IDs 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG ipauuidmagicregen: 2019-01-17T11:00:47Z DEBUG autogenerate 2019-01-17T11:00:47Z DEBUG ipauuidfilter: 2019-01-17T11:00:47Z DEBUG (|(objectclass=ipaObject)(objectclass=ipaAssociation)) 2019-01-17T11:00:47Z DEBUG ipauuidenforce: 2019-01-17T11:00:47Z DEBUG TRUE 2019-01-17T11:00:47Z DEBUG ipauuidexcludesubtree: 2019-01-17T11:00:47Z DEBUG cn=provisioning,dc=local 2019-01-17T11:00:47Z DEBUG ipauuidattr: 2019-01-17T11:00:47Z DEBUG ipaUniqueID 2019-01-17T11:00:47Z DEBUG ipauuidscope: 2019-01-17T11:00:47Z DEBUG dc=local 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Parsing update file '/usr/share/ipa/updates/20-user_private_groups.update' 2019-01-17T11:00:47Z DEBUG New entry: cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG objectclass: 2019-01-17T11:00:47Z DEBUG mepTemplateEntry 2019-01-17T11:00:47Z DEBUG mepMappedAttr: 2019-01-17T11:00:47Z DEBUG cn: $uid 2019-01-17T11:00:47Z DEBUG gidNumber: $uidNumber 2019-01-17T11:00:47Z DEBUG description: User private group for $uid 2019-01-17T11:00:47Z DEBUG mepStaticAttr: 2019-01-17T11:00:47Z DEBUG objectclass: posixgroup 2019-01-17T11:00:47Z DEBUG objectclass: ipaobject 2019-01-17T11:00:47Z DEBUG ipaUniqueId: autogenerate 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG UPG Template 2019-01-17T11:00:47Z DEBUG mepRDNAttr: 2019-01-17T11:00:47Z DEBUG cn 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG objectclass: 2019-01-17T11:00:47Z DEBUG mepTemplateEntry 2019-01-17T11:00:47Z DEBUG mepMappedAttr: 2019-01-17T11:00:47Z DEBUG cn: $uid 2019-01-17T11:00:47Z DEBUG gidNumber: $uidNumber 2019-01-17T11:00:47Z DEBUG description: User private group for $uid 2019-01-17T11:00:47Z DEBUG mepStaticAttr: 2019-01-17T11:00:47Z DEBUG objectclass: posixgroup 2019-01-17T11:00:47Z DEBUG objectclass: ipaobject 2019-01-17T11:00:47Z DEBUG ipaUniqueId: autogenerate 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG UPG Template 2019-01-17T11:00:47Z DEBUG mepRDNAttr: 2019-01-17T11:00:47Z DEBUG cn 2019-01-17T11:00:47Z ERROR Parent DN of cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG New entry: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG UPG Definition 2019-01-17T11:00:47Z DEBUG objectclass: 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG managedBase: 2019-01-17T11:00:47Z DEBUG cn=groups,cn=accounts,dc=local 2019-01-17T11:00:47Z DEBUG originFilter: 2019-01-17T11:00:47Z DEBUG objectclass=posixAccount 2019-01-17T11:00:47Z DEBUG originScope: 2019-01-17T11:00:47Z DEBUG cn=users,cn=accounts,dc=local 2019-01-17T11:00:47Z DEBUG managedTemplate: 2019-01-17T11:00:47Z DEBUG cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG UPG Definition 2019-01-17T11:00:47Z DEBUG objectclass: 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG managedBase: 2019-01-17T11:00:47Z DEBUG cn=groups,cn=accounts,dc=local 2019-01-17T11:00:47Z DEBUG originFilter: 2019-01-17T11:00:47Z DEBUG objectclass=posixAccount 2019-01-17T11:00:47Z DEBUG originScope: 2019-01-17T11:00:47Z DEBUG cn=users,cn=accounts,dc=local 2019-01-17T11:00:47Z DEBUG managedTemplate: 2019-01-17T11:00:47Z DEBUG cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:00:47Z ERROR Parent DN of cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG New entry: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG replace: objectclass=posixAccount not found, skipping 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG Parsing update file '/usr/share/ipa/updates/20-uuid.update' 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=IPK11 Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=IPK11 Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG IPK11 Unique IDs 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG ipauuidmagicregen: 2019-01-17T11:00:47Z DEBUG autogenerate 2019-01-17T11:00:47Z DEBUG ipauuidfilter: 2019-01-17T11:00:47Z DEBUG (objectclass=ipk11Object) 2019-01-17T11:00:47Z DEBUG ipauuidenforce: 2019-01-17T11:00:47Z DEBUG FALSE 2019-01-17T11:00:47Z DEBUG ipauuidscope: 2019-01-17T11:00:47Z DEBUG dc=local 2019-01-17T11:00:47Z DEBUG ipauuidattr: 2019-01-17T11:00:47Z DEBUG ipk11UniqueID 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=IPK11 Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG IPK11 Unique IDs 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG ipauuidmagicregen: 2019-01-17T11:00:47Z DEBUG autogenerate 2019-01-17T11:00:47Z DEBUG ipauuidfilter: 2019-01-17T11:00:47Z DEBUG (objectclass=ipk11Object) 2019-01-17T11:00:47Z DEBUG ipauuidenforce: 2019-01-17T11:00:47Z DEBUG FALSE 2019-01-17T11:00:47Z DEBUG ipauuidscope: 2019-01-17T11:00:47Z DEBUG dc=local 2019-01-17T11:00:47Z DEBUG ipauuidattr: 2019-01-17T11:00:47Z DEBUG ipk11UniqueID 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Parsing update file '/usr/share/ipa/updates/20-whoami.update' 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=whoami,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=whoami,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG whoami-plugin 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG whoami 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG whoami extended operation plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libwhoami-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG extendedop 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG whoami_init 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=whoami,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG whoami-plugin 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG whoami 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG whoami extended operation plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libwhoami-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG extendedop 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG whoami_init 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Parsing update file '/usr/share/ipa/updates/20-winsync_index.update' 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ntUniqueId 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ntUniqueId 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ntUserDomainId 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:00:47Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsIndexType: 2019-01-17T11:00:47Z DEBUG eq 2019-01-17T11:00:47Z DEBUG pres 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsIndex 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ntUserDomainId 2019-01-17T11:00:47Z DEBUG nsSystemIndex: 2019-01-17T11:00:47Z DEBUG false 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Parsing update file '/usr/share/ipa/updates/21-ca_renewal_container.update' 2019-01-17T11:00:47Z DEBUG New entry: cn=ca_renewal,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=ca_renewal,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG add: 'top' to objectClass, current value [] 2019-01-17T11:00:47Z DEBUG add: updated value [u'top'] 2019-01-17T11:00:47Z DEBUG add: 'nsContainer' to objectClass, current value [u'top'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'top', u'nsContainer'] 2019-01-17T11:00:47Z DEBUG add: 'ca_renewal' to cn, current value [] 2019-01-17T11:00:47Z DEBUG add: updated value [u'ca_renewal'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=ca_renewal,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsContainer 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ca_renewal 2019-01-17T11:00:47Z ERROR Parent DN of cn=ca_renewal,cn=ipa,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG Parsing update file '/usr/share/ipa/updates/21-certstore_container.update' 2019-01-17T11:00:47Z DEBUG New entry: cn=certificates,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=certificates,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG add: 'top' to objectClass, current value [] 2019-01-17T11:00:47Z DEBUG add: updated value [u'top'] 2019-01-17T11:00:47Z DEBUG add: 'nsContainer' to objectClass, current value [u'top'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'top', u'nsContainer'] 2019-01-17T11:00:47Z DEBUG add: 'certificates' to cn, current value [] 2019-01-17T11:00:47Z DEBUG add: updated value [u'certificates'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=certificates,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsContainer 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG certificates 2019-01-17T11:00:47Z ERROR Parent DN of cn=certificates,cn=ipa,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG Parsing update file '/usr/share/ipa/updates/21-replicas_container.update' 2019-01-17T11:00:47Z DEBUG New entry: cn=replicas,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=replicas,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG add: 'top' to objectClass, current value [] 2019-01-17T11:00:47Z DEBUG add: updated value [u'top'] 2019-01-17T11:00:47Z DEBUG add: 'nsContainer' to objectClass, current value [u'top'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'top', u'nsContainer'] 2019-01-17T11:00:47Z DEBUG add: 'replicas' to cn, current value [] 2019-01-17T11:00:47Z DEBUG add: updated value [u'replicas'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=replicas,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsContainer 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG replicas 2019-01-17T11:00:47Z ERROR Parent DN of cn=replicas,cn=ipa,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG Parsing update file '/usr/share/ipa/updates/25-referint.update' 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=referential integrity postoperation,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG referint 2019-01-17T11:00:47Z DEBUG nsslapd-plugincontainerscope: 2019-01-17T11:00:47Z DEBUG dc=local 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG referential integrity postoperation 2019-01-17T11:00:47Z DEBUG referint-update-delay: 2019-01-17T11:00:47Z DEBUG 0 2019-01-17T11:00:47Z DEBUG nsslapd-pluginexcludeentryscope: 2019-01-17T11:00:47Z DEBUG cn=provisioning,dc=local 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG referential integrity plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginentryscope: 2019-01-17T11:00:47Z DEBUG dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libreferint-plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:00:47Z DEBUG 40 2019-01-17T11:00:47Z DEBUG referint-logfile: 2019-01-17T11:00:47Z DEBUG /var/log/dirsrv/slapd-LOCAL/referint 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG betxnpostoperation 2019-01-17T11:00:47Z DEBUG referint-membership-attr: 2019-01-17T11:00:47Z DEBUG member 2019-01-17T11:00:47Z DEBUG uniquemember 2019-01-17T11:00:47Z DEBUG owner 2019-01-17T11:00:47Z DEBUG seeAlso 2019-01-17T11:00:47Z DEBUG manager 2019-01-17T11:00:47Z DEBUG secretary 2019-01-17T11:00:47Z DEBUG memberuser 2019-01-17T11:00:47Z DEBUG memberhost 2019-01-17T11:00:47Z DEBUG sourcehost 2019-01-17T11:00:47Z DEBUG memberservice 2019-01-17T11:00:47Z DEBUG managedby 2019-01-17T11:00:47Z DEBUG memberallowcmd 2019-01-17T11:00:47Z DEBUG memberdenycmd 2019-01-17T11:00:47Z DEBUG ipasudorunas 2019-01-17T11:00:47Z DEBUG ipasudorunasgroup 2019-01-17T11:00:47Z DEBUG ipatokenradiusconfiglink 2019-01-17T11:00:47Z DEBUG ipaassignedidview 2019-01-17T11:00:47Z DEBUG ipaallowedtarget 2019-01-17T11:00:47Z DEBUG ipamemberca 2019-01-17T11:00:47Z DEBUG ipamembercertprofile 2019-01-17T11:00:47Z DEBUG ipalocation 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG referint_postop_init 2019-01-17T11:00:47Z DEBUG add: 'manager' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager'] 2019-01-17T11:00:47Z DEBUG add: 'secretary' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary'] 2019-01-17T11:00:47Z DEBUG add: 'memberuser' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser'] 2019-01-17T11:00:47Z DEBUG add: 'memberhost' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost'] 2019-01-17T11:00:47Z DEBUG add: 'sourcehost' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost'] 2019-01-17T11:00:47Z DEBUG add: 'memberservice' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice'] 2019-01-17T11:00:47Z DEBUG add: 'managedby' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby'] 2019-01-17T11:00:47Z DEBUG add: 'memberallowcmd' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd'] 2019-01-17T11:00:47Z DEBUG add: 'memberdenycmd' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd'] 2019-01-17T11:00:47Z DEBUG add: 'ipasudorunas' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas'] 2019-01-17T11:00:47Z DEBUG add: 'ipasudorunasgroup' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup'] 2019-01-17T11:00:47Z DEBUG add: 'ipatokenradiusconfiglink' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink'] 2019-01-17T11:00:47Z DEBUG add: 'ipaassignedidview' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview'] 2019-01-17T11:00:47Z DEBUG add: 'ipaallowedtarget' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget'] 2019-01-17T11:00:47Z DEBUG add: 'ipamemberca' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca'] 2019-01-17T11:00:47Z DEBUG add: 'ipamembercertprofile' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile'] 2019-01-17T11:00:47Z DEBUG add: 'ipalocation' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG referint 2019-01-17T11:00:47Z DEBUG nsslapd-plugincontainerscope: 2019-01-17T11:00:47Z DEBUG dc=local 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG referential integrity postoperation 2019-01-17T11:00:47Z DEBUG referint-update-delay: 2019-01-17T11:00:47Z DEBUG 0 2019-01-17T11:00:47Z DEBUG nsslapd-pluginexcludeentryscope: 2019-01-17T11:00:47Z DEBUG cn=provisioning,dc=local 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG referential integrity plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginentryscope: 2019-01-17T11:00:47Z DEBUG dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libreferint-plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:00:47Z DEBUG 40 2019-01-17T11:00:47Z DEBUG referint-logfile: 2019-01-17T11:00:47Z DEBUG /var/log/dirsrv/slapd-LOCAL/referint 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG betxnpostoperation 2019-01-17T11:00:47Z DEBUG referint-membership-attr: 2019-01-17T11:00:47Z DEBUG member 2019-01-17T11:00:47Z DEBUG uniquemember 2019-01-17T11:00:47Z DEBUG owner 2019-01-17T11:00:47Z DEBUG seeAlso 2019-01-17T11:00:47Z DEBUG manager 2019-01-17T11:00:47Z DEBUG secretary 2019-01-17T11:00:47Z DEBUG memberuser 2019-01-17T11:00:47Z DEBUG memberhost 2019-01-17T11:00:47Z DEBUG sourcehost 2019-01-17T11:00:47Z DEBUG memberservice 2019-01-17T11:00:47Z DEBUG managedby 2019-01-17T11:00:47Z DEBUG memberallowcmd 2019-01-17T11:00:47Z DEBUG memberdenycmd 2019-01-17T11:00:47Z DEBUG ipasudorunas 2019-01-17T11:00:47Z DEBUG ipasudorunasgroup 2019-01-17T11:00:47Z DEBUG ipatokenradiusconfiglink 2019-01-17T11:00:47Z DEBUG ipaassignedidview 2019-01-17T11:00:47Z DEBUG ipaallowedtarget 2019-01-17T11:00:47Z DEBUG ipamemberca 2019-01-17T11:00:47Z DEBUG ipamembercertprofile 2019-01-17T11:00:47Z DEBUG ipalocation 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG referint_postop_init 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG Parsing update file '/usr/share/ipa/updates/30-provisioning.update' 2019-01-17T11:00:47Z DEBUG New entry: cn=provisioning,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=provisioning,dc=local 2019-01-17T11:00:47Z DEBUG objectclass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsContainer 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG provisioning 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=provisioning,dc=local 2019-01-17T11:00:47Z DEBUG objectclass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsContainer 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG provisioning 2019-01-17T11:00:47Z DEBUG Unhandled LDAPError: OPERATIONS_ERROR: {'desc': 'Operations error'} 2019-01-17T11:00:47Z ERROR Add failure Operations error: 2019-01-17T11:00:47Z DEBUG New entry: cn=accounts,cn=provisioning,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=accounts,cn=provisioning,dc=local 2019-01-17T11:00:47Z DEBUG objectclass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsContainer 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG accounts 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=accounts,cn=provisioning,dc=local 2019-01-17T11:00:47Z DEBUG objectclass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsContainer 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG accounts 2019-01-17T11:00:47Z ERROR Parent DN of cn=accounts,cn=provisioning,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG New entry: cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:00:47Z DEBUG objectclass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsContainer 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG staged users 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:00:47Z DEBUG objectclass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsContainer 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG staged users 2019-01-17T11:00:47Z ERROR Parent DN of cn=staged users,cn=accounts,cn=provisioning,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG New entry: cn=deleted users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=deleted users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:00:47Z DEBUG objectclass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsContainer 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG deleted users 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=deleted users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:00:47Z DEBUG objectclass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsContainer 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG deleted users 2019-01-17T11:00:47Z ERROR Parent DN of cn=deleted users,cn=accounts,cn=provisioning,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG New entry: cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:00:47Z DEBUG remove: '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=local";)' from aci, current value [] 2019-01-17T11:00:47Z DEBUG remove: '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=local";)' not in aci 2019-01-17T11:00:47Z DEBUG add: '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' to aci, current value [] 2019-01-17T11:00:47Z DEBUG add: updated value [u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:00:47Z DEBUG aci: 2019-01-17T11:00:47Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:00:47Z ERROR Parent DN of cn=staged users,cn=accounts,cn=provisioning,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG New entry: cn=deleted users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=deleted users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:00:47Z DEBUG remove: '(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=local";)' from aci, current value [] 2019-01-17T11:00:47Z DEBUG remove: '(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=local";)' not in aci 2019-01-17T11:00:47Z DEBUG add: '(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' to aci, current value [] 2019-01-17T11:00:47Z DEBUG add: updated value [u'(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:00:47Z DEBUG add: '(targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";)' to aci, current value [u'(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";)'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=deleted users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:00:47Z DEBUG aci: 2019-01-17T11:00:47Z DEBUG (targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:00:47Z DEBUG (targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";) 2019-01-17T11:00:47Z ERROR Parent DN of cn=deleted users,cn=accounts,cn=provisioning,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG New entry: cn=provisioning accounts lock,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=provisioning accounts lock,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG cosSuperDefinition 2019-01-17T11:00:47Z DEBUG cosPointerDefinition 2019-01-17T11:00:47Z DEBUG ldapSubEntry 2019-01-17T11:00:47Z DEBUG costemplatedn: 2019-01-17T11:00:47Z DEBUG cn=Inactivation cos template,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG provisioning accounts lock 2019-01-17T11:00:47Z DEBUG cosAttribute: 2019-01-17T11:00:47Z DEBUG nsaccountlock operational 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=provisioning accounts lock,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG cosSuperDefinition 2019-01-17T11:00:47Z DEBUG cosPointerDefinition 2019-01-17T11:00:47Z DEBUG ldapSubEntry 2019-01-17T11:00:47Z DEBUG costemplatedn: 2019-01-17T11:00:47Z DEBUG cn=Inactivation cos template,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG provisioning accounts lock 2019-01-17T11:00:47Z DEBUG cosAttribute: 2019-01-17T11:00:47Z DEBUG nsaccountlock operational 2019-01-17T11:00:47Z ERROR Parent DN of cn=provisioning accounts lock,cn=accounts,cn=provisioning,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG New entry: cn=Inactivation cos template,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=Inactivation cos template,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG cosTemplate 2019-01-17T11:00:47Z DEBUG cosPriority: 2019-01-17T11:00:47Z DEBUG 1 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Inactivation cos template 2019-01-17T11:00:47Z DEBUG nsAccountLock: 2019-01-17T11:00:47Z DEBUG true 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=Inactivation cos template,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG cosTemplate 2019-01-17T11:00:47Z DEBUG cosPriority: 2019-01-17T11:00:47Z DEBUG 1 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Inactivation cos template 2019-01-17T11:00:47Z DEBUG nsAccountLock: 2019-01-17T11:00:47Z DEBUG true 2019-01-17T11:00:47Z ERROR Parent DN of cn=Inactivation cos template,cn=accounts,cn=provisioning,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG Parsing update file '/usr/share/ipa/updates/30-s4u2proxy.update' 2019-01-17T11:00:47Z DEBUG New entry: cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG nsContainer 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG s4u2proxy 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG nsContainer 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG s4u2proxy 2019-01-17T11:00:47Z ERROR Parent DN of cn=s4u2proxy,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG New entry: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG ipaKrb5DelegationACL 2019-01-17T11:00:47Z DEBUG groupOfPrincipals 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG memberPrincipal: 2019-01-17T11:00:47Z DEBUG HTTP/centos75.local@LOCAL 2019-01-17T11:00:47Z DEBUG ipaAllowedTarget: 2019-01-17T11:00:47Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ipa-http-delegation 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG ipaKrb5DelegationACL 2019-01-17T11:00:47Z DEBUG groupOfPrincipals 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG memberPrincipal: 2019-01-17T11:00:47Z DEBUG HTTP/centos75.local@LOCAL 2019-01-17T11:00:47Z DEBUG ipaAllowedTarget: 2019-01-17T11:00:47Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ipa-http-delegation 2019-01-17T11:00:47Z ERROR Parent DN of cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG New entry: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG groupOfPrincipals 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG memberPrincipal: 2019-01-17T11:00:47Z DEBUG ldap/centos75.local@LOCAL 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ipa-ldap-delegation-targets 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG groupOfPrincipals 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG memberPrincipal: 2019-01-17T11:00:47Z DEBUG ldap/centos75.local@LOCAL 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ipa-ldap-delegation-targets 2019-01-17T11:00:47Z ERROR Parent DN of cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG New entry: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG add: 'HTTP/centos75.local@LOCAL' to memberPrincipal, current value [] 2019-01-17T11:00:47Z DEBUG add: updated value [u'HTTP/centos75.local@LOCAL'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG memberPrincipal: 2019-01-17T11:00:47Z DEBUG HTTP/centos75.local@LOCAL 2019-01-17T11:00:47Z ERROR Parent DN of cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG New entry: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG add: 'ldap/centos75.local@LOCAL' to memberPrincipal, current value [] 2019-01-17T11:00:47Z DEBUG add: updated value [u'ldap/centos75.local@LOCAL'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG memberPrincipal: 2019-01-17T11:00:47Z DEBUG ldap/centos75.local@LOCAL 2019-01-17T11:00:47Z ERROR Parent DN of cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG Parsing update file '/usr/share/ipa/updates/37-locations.update' 2019-01-17T11:00:47Z DEBUG New entry: cn=locations,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=locations,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG nsContainer 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG locations 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=locations,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG nsContainer 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG locations 2019-01-17T11:00:47Z ERROR Parent DN of cn=locations,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG Parsing update file '/usr/share/ipa/updates/40-automember.update' 2019-01-17T11:00:47Z DEBUG Updating existing entry: cn=Auto Membership Plugin,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG Auto Membership 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Auto Membership Plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG Auto Membership plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libautomember-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginConfigArea: 2019-01-17T11:00:47Z DEBUG cn=automember,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG betxnpreoperation 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG automember_init 2019-01-17T11:00:47Z DEBUG addifnew: 'cn=automember,cn=etc,dc=local' to nsslapd-pluginConfigArea, current value [u'cn=automember,cn=etc,dc=local'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2019-01-17T11:00:47Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:47Z DEBUG Auto Membership 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Auto Membership Plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:47Z DEBUG 1.3.8.4 2019-01-17T11:00:47Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:47Z DEBUG Auto Membership plugin 2019-01-17T11:00:47Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:47Z DEBUG on 2019-01-17T11:00:47Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:47Z DEBUG libautomember-plugin 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsSlapdPlugin 2019-01-17T11:00:47Z DEBUG extensibleObject 2019-01-17T11:00:47Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:47Z DEBUG database 2019-01-17T11:00:47Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:47Z DEBUG 389 Project 2019-01-17T11:00:47Z DEBUG nsslapd-pluginConfigArea: 2019-01-17T11:00:47Z DEBUG cn=automember,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:47Z DEBUG betxnpreoperation 2019-01-17T11:00:47Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:47Z DEBUG automember_init 2019-01-17T11:00:47Z DEBUG [] 2019-01-17T11:00:47Z DEBUG Updated 0 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG New entry: cn=automember,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=automember,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsContainer 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG automember 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=automember,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG nsContainer 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG automember 2019-01-17T11:00:47Z ERROR Parent DN of cn=automember,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG New entry: cn=Hostgroup,cn=automember,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=Hostgroup,cn=automember,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG objectclass: 2019-01-17T11:00:47Z DEBUG autoMemberDefinition 2019-01-17T11:00:47Z DEBUG autoMemberGroupingAttr: 2019-01-17T11:00:47Z DEBUG member:dn 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Hostgroup 2019-01-17T11:00:47Z DEBUG autoMemberScope: 2019-01-17T11:00:47Z DEBUG cn=computers,cn=accounts,dc=local 2019-01-17T11:00:47Z DEBUG autoMemberFilter: 2019-01-17T11:00:47Z DEBUG objectclass=ipaHost 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=Hostgroup,cn=automember,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG objectclass: 2019-01-17T11:00:47Z DEBUG autoMemberDefinition 2019-01-17T11:00:47Z DEBUG autoMemberGroupingAttr: 2019-01-17T11:00:47Z DEBUG member:dn 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Hostgroup 2019-01-17T11:00:47Z DEBUG autoMemberScope: 2019-01-17T11:00:47Z DEBUG cn=computers,cn=accounts,dc=local 2019-01-17T11:00:47Z DEBUG autoMemberFilter: 2019-01-17T11:00:47Z DEBUG objectclass=ipaHost 2019-01-17T11:00:47Z ERROR Parent DN of cn=Hostgroup,cn=automember,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG New entry: cn=Group,cn=automember,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=Group,cn=automember,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG objectclass: 2019-01-17T11:00:47Z DEBUG autoMemberDefinition 2019-01-17T11:00:47Z DEBUG autoMemberGroupingAttr: 2019-01-17T11:00:47Z DEBUG member:dn 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Group 2019-01-17T11:00:47Z DEBUG autoMemberScope: 2019-01-17T11:00:47Z DEBUG cn=users,cn=accounts,dc=local 2019-01-17T11:00:47Z DEBUG autoMemberFilter: 2019-01-17T11:00:47Z DEBUG objectclass=posixAccount 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=Group,cn=automember,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG objectclass: 2019-01-17T11:00:47Z DEBUG autoMemberDefinition 2019-01-17T11:00:47Z DEBUG autoMemberGroupingAttr: 2019-01-17T11:00:47Z DEBUG member:dn 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Group 2019-01-17T11:00:47Z DEBUG autoMemberScope: 2019-01-17T11:00:47Z DEBUG cn=users,cn=accounts,dc=local 2019-01-17T11:00:47Z DEBUG autoMemberFilter: 2019-01-17T11:00:47Z DEBUG objectclass=posixAccount 2019-01-17T11:00:47Z ERROR Parent DN of cn=Group,cn=automember,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG Parsing update file '/usr/share/ipa/updates/40-certprofile.update' 2019-01-17T11:00:47Z DEBUG New entry: cn=ca,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=ca,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG nsContainer 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ca 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=ca,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG nsContainer 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG ca 2019-01-17T11:00:47Z DEBUG Unhandled LDAPError: OPERATIONS_ERROR: {'desc': 'Operations error'} 2019-01-17T11:00:47Z ERROR Add failure Operations error: 2019-01-17T11:00:47Z DEBUG New entry: cn=certprofiles,cn=ca,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=certprofiles,cn=ca,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG nsContainer 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG certprofiles 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=certprofiles,cn=ca,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG nsContainer 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG certprofiles 2019-01-17T11:00:47Z ERROR Parent DN of cn=certprofiles,cn=ca,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG Parsing update file '/usr/share/ipa/updates/40-delegation.update' 2019-01-17T11:00:47Z DEBUG New entry: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG groupofnames 2019-01-17T11:00:47Z DEBUG nestedgroup 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Write IPA Configuration 2019-01-17T11:00:47Z DEBUG description: 2019-01-17T11:00:47Z DEBUG Write IPA Configuration 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG groupofnames 2019-01-17T11:00:47Z DEBUG nestedgroup 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Write IPA Configuration 2019-01-17T11:00:47Z DEBUG description: 2019-01-17T11:00:47Z DEBUG Write IPA Configuration 2019-01-17T11:00:47Z ERROR Parent DN of cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG New entry: cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG groupofnames 2019-01-17T11:00:47Z DEBUG ipapermission 2019-01-17T11:00:47Z DEBUG member: 2019-01-17T11:00:47Z DEBUG cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Write IPA Configuration 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG groupofnames 2019-01-17T11:00:47Z DEBUG ipapermission 2019-01-17T11:00:47Z DEBUG member: 2019-01-17T11:00:47Z DEBUG cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Write IPA Configuration 2019-01-17T11:00:47Z ERROR Parent DN of cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG Updating existing entry: dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG domain 2019-01-17T11:00:47Z DEBUG domainRelatedObject 2019-01-17T11:00:47Z DEBUG nisDomainObject 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG associatedDomain: 2019-01-17T11:00:47Z DEBUG local 2019-01-17T11:00:47Z DEBUG dc: 2019-01-17T11:00:47Z DEBUG local 2019-01-17T11:00:47Z DEBUG nisDomain: 2019-01-17T11:00:47Z DEBUG local 2019-01-17T11:00:47Z DEBUG add: '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";)' to aci, current value [] 2019-01-17T11:00:47Z DEBUG add: updated value [u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG domain 2019-01-17T11:00:47Z DEBUG domainRelatedObject 2019-01-17T11:00:47Z DEBUG nisDomainObject 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG aci: 2019-01-17T11:00:47Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:47Z DEBUG associatedDomain: 2019-01-17T11:00:47Z DEBUG local 2019-01-17T11:00:47Z DEBUG dc: 2019-01-17T11:00:47Z DEBUG local 2019-01-17T11:00:47Z DEBUG nisDomain: 2019-01-17T11:00:47Z DEBUG local 2019-01-17T11:00:47Z DEBUG [(2, u'aci', [u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";)'])] 2019-01-17T11:00:47Z DEBUG Updated 1 2019-01-17T11:00:47Z DEBUG Done 2019-01-17T11:00:47Z DEBUG New entry: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG nestedgroup 2019-01-17T11:00:47Z DEBUG groupofnames 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG HBAC Administrator 2019-01-17T11:00:47Z DEBUG description: 2019-01-17T11:00:47Z DEBUG HBAC Administrator 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG nestedgroup 2019-01-17T11:00:47Z DEBUG groupofnames 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG HBAC Administrator 2019-01-17T11:00:47Z DEBUG description: 2019-01-17T11:00:47Z DEBUG HBAC Administrator 2019-01-17T11:00:47Z ERROR Parent DN of cn=HBAC Administrator,cn=privileges,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG New entry: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG nestedgroup 2019-01-17T11:00:47Z DEBUG groupofnames 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Sudo Administrator 2019-01-17T11:00:47Z DEBUG description: 2019-01-17T11:00:47Z DEBUG Sudo Administrator 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG nestedgroup 2019-01-17T11:00:47Z DEBUG groupofnames 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Sudo Administrator 2019-01-17T11:00:47Z DEBUG description: 2019-01-17T11:00:47Z DEBUG Sudo Administrator 2019-01-17T11:00:47Z ERROR Parent DN of cn=Sudo Administrator,cn=privileges,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG New entry: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG nestedgroup 2019-01-17T11:00:47Z DEBUG groupofnames 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Password Policy Administrator 2019-01-17T11:00:47Z DEBUG description: 2019-01-17T11:00:47Z DEBUG Password Policy Administrator 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG nestedgroup 2019-01-17T11:00:47Z DEBUG groupofnames 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG Password Policy Administrator 2019-01-17T11:00:47Z DEBUG description: 2019-01-17T11:00:47Z DEBUG Password Policy Administrator 2019-01-17T11:00:47Z ERROR Parent DN of cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG New entry: cn=Host Enrollment,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=Host Enrollment,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:47Z DEBUG add: 'cn=admins,cn=groups,cn=accounts,dc=local' to member, current value [] 2019-01-17T11:00:47Z DEBUG add: updated value [u'cn=admins,cn=groups,cn=accounts,dc=local'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=Host Enrollment,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:47Z DEBUG member: 2019-01-17T11:00:47Z DEBUG cn=admins,cn=groups,cn=accounts,dc=local 2019-01-17T11:00:47Z ERROR Parent DN of cn=Host Enrollment,cn=privileges,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG New entry: dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: dc=local 2019-01-17T11:00:47Z DEBUG remove: '(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "Add DNS entries";allow (add) groupdn = "ldap:///cn=add dns entries,cn=permissions,cn=pbac,dc=local";)' from aci, current value [] 2019-01-17T11:00:47Z DEBUG remove: '(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "Add DNS entries";allow (add) groupdn = "ldap:///cn=add dns entries,cn=permissions,cn=pbac,dc=local";)' not in aci 2019-01-17T11:00:47Z DEBUG remove: '(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "Remove DNS entries";allow (delete) groupdn = "ldap:///cn=remove dns entries,cn=permissions,cn=pbac,dc=local";)' from aci, current value [] 2019-01-17T11:00:47Z DEBUG remove: '(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "Remove DNS entries";allow (delete) groupdn = "ldap:///cn=remove dns entries,cn=permissions,cn=pbac,dc=local";)' not in aci 2019-01-17T11:00:47Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy")(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "Update DNS entries";allow (write) groupdn = "ldap:///cn=update dns entries,cn=permissions,cn=pbac,dc=local";)' from aci, current value [] 2019-01-17T11:00:47Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy")(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "Update DNS entries";allow (write) groupdn = "ldap:///cn=update dns entries,cn=permissions,cn=pbac,dc=local";)' not in aci 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: dc=local 2019-01-17T11:00:47Z DEBUG New entry: cn=SELinux User Map Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=SELinux User Map Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG groupofnames 2019-01-17T11:00:47Z DEBUG nestedgroup 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG SELinux User Map Administrators 2019-01-17T11:00:47Z DEBUG description: 2019-01-17T11:00:47Z DEBUG SELinux User Map Administrators 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=SELinux User Map Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:47Z DEBUG objectClass: 2019-01-17T11:00:47Z DEBUG top 2019-01-17T11:00:47Z DEBUG groupofnames 2019-01-17T11:00:47Z DEBUG nestedgroup 2019-01-17T11:00:47Z DEBUG cn: 2019-01-17T11:00:47Z DEBUG SELinux User Map Administrators 2019-01-17T11:00:47Z DEBUG description: 2019-01-17T11:00:47Z DEBUG SELinux User Map Administrators 2019-01-17T11:00:47Z ERROR Parent DN of cn=SELinux User Map Administrators,cn=privileges,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG New entry: cn=ipa,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=ipa,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG remove: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) userdn = "ldap:///fqdn=centos75.local,cn=computers,cn=accounts,dc=local";)' from aci, current value [] 2019-01-17T11:00:47Z DEBUG remove: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) userdn = "ldap:///fqdn=centos75.local,cn=computers,cn=accounts,dc=local";)' not in aci 2019-01-17T11:00:47Z DEBUG remove: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) userdn = "ldap:///fqdn=centos75.local,cn=computers,cn=accounts,dc=local";)' from aci, current value [] 2019-01-17T11:00:47Z DEBUG remove: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) userdn = "ldap:///fqdn=centos75.local,cn=computers,cn=accounts,dc=local";)' not in aci 2019-01-17T11:00:47Z DEBUG add: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)' to aci, current value [] 2019-01-17T11:00:47Z DEBUG add: updated value [u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)'] 2019-01-17T11:00:47Z DEBUG add: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)' to aci, current value [u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)'] 2019-01-17T11:00:47Z DEBUG add: updated value [u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=ipa,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG aci: 2019-01-17T11:00:47Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";) 2019-01-17T11:00:47Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";) 2019-01-17T11:00:47Z ERROR Parent DN of cn=ipa,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG New entry: cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local 2019-01-17T11:00:47Z DEBUG add: 'cn=Host Administrators,cn=privileges,cn=pbac,dc=local' to member, current value [] 2019-01-17T11:00:47Z DEBUG add: updated value [u'cn=Host Administrators,cn=privileges,cn=pbac,dc=local'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local 2019-01-17T11:00:47Z DEBUG member: 2019-01-17T11:00:47Z DEBUG cn=Host Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:47Z ERROR Parent DN of cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG New entry: cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local 2019-01-17T11:00:47Z DEBUG add: 'cn=Host Administrators,cn=privileges,cn=pbac,dc=local' to member, current value [] 2019-01-17T11:00:47Z DEBUG add: updated value [u'cn=Host Administrators,cn=privileges,cn=pbac,dc=local'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local 2019-01-17T11:00:47Z DEBUG member: 2019-01-17T11:00:47Z DEBUG cn=Host Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:47Z ERROR Parent DN of cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG New entry: cn=ipa,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=ipa,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG remove: '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=local")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) userdn = "ldap:///fqdn=centos75.local,cn=computers,cn=accounts,dc=local";)' from aci, current value [] 2019-01-17T11:00:47Z DEBUG remove: '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=local")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) userdn = "ldap:///fqdn=centos75.local,cn=computers,cn=accounts,dc=local";)' not in aci 2019-01-17T11:00:47Z DEBUG add: '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=local")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)' to aci, current value [] 2019-01-17T11:00:47Z DEBUG add: updated value [u'(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=local")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=ipa,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG aci: 2019-01-17T11:00:47Z DEBUG (target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=local")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";) 2019-01-17T11:00:47Z ERROR Parent DN of cn=ipa,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:47Z DEBUG New entry: cn=certificates,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Initial value 2019-01-17T11:00:47Z DEBUG dn: cn=certificates,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG remove: '(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) userdn = "ldap:///fqdn=centos75.local,cn=computers,cn=accounts,dc=local";)' from aci, current value [] 2019-01-17T11:00:47Z DEBUG remove: '(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) userdn = "ldap:///fqdn=centos75.local,cn=computers,cn=accounts,dc=local";)' not in aci 2019-01-17T11:00:47Z DEBUG add: '(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)' to aci, current value [] 2019-01-17T11:00:47Z DEBUG add: updated value [u'(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)'] 2019-01-17T11:00:47Z DEBUG --------------------------------------------- 2019-01-17T11:00:47Z DEBUG Final value after applying updates 2019-01-17T11:00:47Z DEBUG dn: cn=certificates,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:47Z DEBUG aci: 2019-01-17T11:00:47Z DEBUG (targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";) 2019-01-17T11:00:48Z ERROR Parent DN of cn=certificates,cn=ipa,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=Automember Task Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=Automember Task Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Automember Task Administrator 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG Automember Task Administrator 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=Automember Task Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Automember Task Administrator 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG Automember Task Administrator 2019-01-17T11:00:48Z ERROR Parent DN of cn=Automember Task Administrator,cn=privileges,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG ipapermission 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=Automember Task Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG ipapermissiontype: 2019-01-17T11:00:48Z DEBUG SYSTEM 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Add Automember Rebuild Membership Task 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG ipapermission 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=Automember Task Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG ipapermissiontype: 2019-01-17T11:00:48Z DEBUG SYSTEM 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Add Automember Rebuild Membership Task 2019-01-17T11:00:48Z ERROR Parent DN of cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG Updating existing entry: cn=config 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-betype: 2019-01-17T11:00:48Z DEBUG ldbm database 2019-01-17T11:00:48Z DEBUG nsslapd-nagle: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-referralmode: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:00:48Z DEBUG 64 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 500 2019-01-17T11:00:48Z DEBUG passwordMinAlphas: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-readonly: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordLegacyPolicy: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:00:48Z DEBUG allowed 2019-01-17T11:00:48Z DEBUG passwordMinUppers: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-plugin: 2019-01-17T11:00:48Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:00:48Z DEBUG 2097152 2019-01-17T11:00:48Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:00:48Z DEBUG 20971520 2019-01-17T11:00:48Z DEBUG nsslapd-timelimit: 2019-01-17T11:00:48Z DEBUG 3600 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordMinTokenLength: 2019-01-17T11:00:48Z DEBUG 3 2019-01-17T11:00:48Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:00:48Z DEBUG -10 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG week 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG passwordMinAge: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG week 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:00:48Z DEBUG 60 2019-01-17T11:00:48Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:00:48Z DEBUG 1024 2019-01-17T11:00:48Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordInHistory: 2019-01-17T11:00:48Z DEBUG 6 2019-01-17T11:00:48Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-conntablesize: 2019-01-17T11:00:48Z DEBUG 16384 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG nsslapd-saslpath: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG passwordMaxAge: 2019-01-17T11:00:48Z DEBUG 8640000 2019-01-17T11:00:48Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:00:48Z DEBUG gidNumber 2019-01-17T11:00:48Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG day 2019-01-17T11:00:48Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-csnlogging: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-tmpdir: 2019-01-17T11:00:48Z DEBUG /tmp 2019-01-17T11:00:48Z DEBUG passwordResetFailureCount: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-counters: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-svrtab: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG nsslapd-minssf: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-schemadir: 2019-01-17T11:00:48Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:00:48Z DEBUG nsslapd-localuser: 2019-01-17T11:00:48Z DEBUG dirsrv 2019-01-17T11:00:48Z DEBUG nsslapd-security: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordChange: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-port 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:00:48Z DEBUG passwordMaxFailure: 2019-01-17T11:00:48Z DEBUG 3 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:00:48Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:00:48Z DEBUG 128 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:00:48Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-rootdn: 2019-01-17T11:00:48Z DEBUG cn=Directory Manager 2019-01-17T11:00:48Z DEBUG nsslapd-ldifdir: 2019-01-17T11:00:48Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:00:48Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG passwordMustChange: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordExp: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-logging-backend: 2019-01-17T11:00:48Z DEBUG dirsrv-log 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:48Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG aci: 2019-01-17T11:00:48Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:00:48Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:00:48Z DEBUG cn=Directory Manager 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordMinLength: 2019-01-17T11:00:48Z DEBUG 8 2019-01-17T11:00:48Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-idletimeout: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:00:48Z DEBUG -10 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG week 2019-01-17T11:00:48Z DEBUG nsslapd-securePort: 2019-01-17T11:00:48Z DEBUG 636 2019-01-17T11:00:48Z DEBUG nsslapd-snmp-index: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG config 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG extensibleObject 2019-01-17T11:00:48Z DEBUG nsslapdConfig 2019-01-17T11:00:48Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordSendExpiringTime: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-hash-filters: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:00:48Z DEBUG next 2019-01-17T11:00:48Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:00:48Z DEBUG -10 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-listenhost: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordCheckSyntax: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordGraceLimit: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG passwordWarning: 2019-01-17T11:00:48Z DEBUG 86400 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-instancedir: 2019-01-17T11:00:48Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-config: 2019-01-17T11:00:48Z DEBUG cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-versionstring: 2019-01-17T11:00:48Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:00:48Z DEBUG 256 2019-01-17T11:00:48Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:00:48Z DEBUG 2097152 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:00:48Z DEBUG SSHA512 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG passwordLockout: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-lockdir: 2019-01-17T11:00:48Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-certdir: 2019-01-17T11:00:48Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 10 2019-01-17T11:00:48Z DEBUG nsslapd-backendconfig: 2019-01-17T11:00:48Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-threadnumber: 2019-01-17T11:00:48Z DEBUG 24 2019-01-17T11:00:48Z DEBUG nsslapd-schemamod: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-localhost: 2019-01-17T11:00:48Z DEBUG centos75.local 2019-01-17T11:00:48Z DEBUG nsslapd-bakdir: 2019-01-17T11:00:48Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:00:48Z DEBUG passwordMin8bit: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:00:48Z DEBUG uidNumber 2019-01-17T11:00:48Z DEBUG nsslapd-validate-cert: 2019-01-17T11:00:48Z DEBUG warn 2019-01-17T11:00:48Z DEBUG passwordMinCategories: 2019-01-17T11:00:48Z DEBUG 3 2019-01-17T11:00:48Z DEBUG passwordMinLowers: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordAdminDN: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordMinSpecials: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-lastmod: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:00:48Z DEBUG 40 2019-01-17T11:00:48Z DEBUG passwordMaxRepeats: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:00:48Z DEBUG -1 2019-01-17T11:00:48Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:00:48Z DEBUG none 2019-01-17T11:00:48Z DEBUG nsslapd-result-tweak: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG passwordUnlock: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-schemacheck: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-maxbersize: 2019-01-17T11:00:48Z DEBUG 209715200 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:00:48Z DEBUG dc=example,dc=com 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-localssf: 2019-01-17T11:00:48Z DEBUG 71 2019-01-17T11:00:48Z DEBUG nsslapd-sizelimit: 2019-01-17T11:00:48Z DEBUG 2000 2019-01-17T11:00:48Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:00:48Z DEBUG dc=local 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:00:48Z DEBUG 2097152 2019-01-17T11:00:48Z DEBUG passwordLockoutDuration: 2019-01-17T11:00:48Z DEBUG 3600 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-port: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:00:48Z DEBUG cn=schema 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG cn=monitor 2019-01-17T11:00:48Z DEBUG cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-rootpw: 2019-01-17T11:00:48Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:00:48Z DEBUG 300000 2019-01-17T11:00:48Z DEBUG nsslapd-workingdir: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-rundir: 2019-01-17T11:00:48Z DEBUG /var/run/dirsrv 2019-01-17T11:00:48Z DEBUG nsslapd-schemareplace: 2019-01-17T11:00:48Z DEBUG replication-only 2019-01-17T11:00:48Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:00:48Z DEBUG 16384 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:00:48Z DEBUG 10000 2019-01-17T11:00:48Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordMinDigits: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG passwordStorageScheme: 2019-01-17T11:00:48Z DEBUG SSHA512 2019-01-17T11:00:48Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG add: '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";)' to aci, current value [u'(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";)', u'(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:00:48Z DEBUG add: updated value [u'(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";)', u'(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";)', u'(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-betype: 2019-01-17T11:00:48Z DEBUG ldbm database 2019-01-17T11:00:48Z DEBUG nsslapd-nagle: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-referralmode: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:00:48Z DEBUG 64 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 500 2019-01-17T11:00:48Z DEBUG passwordMinAlphas: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-readonly: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordLegacyPolicy: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:00:48Z DEBUG allowed 2019-01-17T11:00:48Z DEBUG passwordMinUppers: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-plugin: 2019-01-17T11:00:48Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:00:48Z DEBUG 2097152 2019-01-17T11:00:48Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:00:48Z DEBUG 20971520 2019-01-17T11:00:48Z DEBUG nsslapd-timelimit: 2019-01-17T11:00:48Z DEBUG 3600 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordMinTokenLength: 2019-01-17T11:00:48Z DEBUG 3 2019-01-17T11:00:48Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:00:48Z DEBUG -10 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG week 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG passwordMinAge: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG week 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:00:48Z DEBUG 60 2019-01-17T11:00:48Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:00:48Z DEBUG 1024 2019-01-17T11:00:48Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordInHistory: 2019-01-17T11:00:48Z DEBUG 6 2019-01-17T11:00:48Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-conntablesize: 2019-01-17T11:00:48Z DEBUG 16384 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG nsslapd-saslpath: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG passwordMaxAge: 2019-01-17T11:00:48Z DEBUG 8640000 2019-01-17T11:00:48Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:00:48Z DEBUG gidNumber 2019-01-17T11:00:48Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG day 2019-01-17T11:00:48Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-csnlogging: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-tmpdir: 2019-01-17T11:00:48Z DEBUG /tmp 2019-01-17T11:00:48Z DEBUG passwordResetFailureCount: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-counters: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-svrtab: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG nsslapd-minssf: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-schemadir: 2019-01-17T11:00:48Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:00:48Z DEBUG nsslapd-localuser: 2019-01-17T11:00:48Z DEBUG dirsrv 2019-01-17T11:00:48Z DEBUG nsslapd-security: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordChange: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-port 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:00:48Z DEBUG passwordMaxFailure: 2019-01-17T11:00:48Z DEBUG 3 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:00:48Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:00:48Z DEBUG 128 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:00:48Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-rootdn: 2019-01-17T11:00:48Z DEBUG cn=Directory Manager 2019-01-17T11:00:48Z DEBUG nsslapd-ldifdir: 2019-01-17T11:00:48Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:00:48Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG passwordMustChange: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordExp: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-logging-backend: 2019-01-17T11:00:48Z DEBUG dirsrv-log 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:48Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG aci: 2019-01-17T11:00:48Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:00:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:00:48Z DEBUG cn=Directory Manager 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordMinLength: 2019-01-17T11:00:48Z DEBUG 8 2019-01-17T11:00:48Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-idletimeout: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:00:48Z DEBUG -10 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG week 2019-01-17T11:00:48Z DEBUG nsslapd-securePort: 2019-01-17T11:00:48Z DEBUG 636 2019-01-17T11:00:48Z DEBUG nsslapd-snmp-index: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG config 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG extensibleObject 2019-01-17T11:00:48Z DEBUG nsslapdConfig 2019-01-17T11:00:48Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordSendExpiringTime: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-hash-filters: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:00:48Z DEBUG next 2019-01-17T11:00:48Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:00:48Z DEBUG -10 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-listenhost: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordCheckSyntax: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordGraceLimit: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG passwordWarning: 2019-01-17T11:00:48Z DEBUG 86400 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-instancedir: 2019-01-17T11:00:48Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-config: 2019-01-17T11:00:48Z DEBUG cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-versionstring: 2019-01-17T11:00:48Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:00:48Z DEBUG 256 2019-01-17T11:00:48Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:00:48Z DEBUG 2097152 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:00:48Z DEBUG SSHA512 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG passwordLockout: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-lockdir: 2019-01-17T11:00:48Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-certdir: 2019-01-17T11:00:48Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 10 2019-01-17T11:00:48Z DEBUG nsslapd-backendconfig: 2019-01-17T11:00:48Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-threadnumber: 2019-01-17T11:00:48Z DEBUG 24 2019-01-17T11:00:48Z DEBUG nsslapd-schemamod: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-localhost: 2019-01-17T11:00:48Z DEBUG centos75.local 2019-01-17T11:00:48Z DEBUG nsslapd-bakdir: 2019-01-17T11:00:48Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:00:48Z DEBUG passwordMin8bit: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:00:48Z DEBUG uidNumber 2019-01-17T11:00:48Z DEBUG nsslapd-validate-cert: 2019-01-17T11:00:48Z DEBUG warn 2019-01-17T11:00:48Z DEBUG passwordMinCategories: 2019-01-17T11:00:48Z DEBUG 3 2019-01-17T11:00:48Z DEBUG passwordMinLowers: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordAdminDN: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordMinSpecials: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-lastmod: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:00:48Z DEBUG 40 2019-01-17T11:00:48Z DEBUG passwordMaxRepeats: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:00:48Z DEBUG -1 2019-01-17T11:00:48Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:00:48Z DEBUG none 2019-01-17T11:00:48Z DEBUG nsslapd-result-tweak: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG passwordUnlock: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-schemacheck: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-maxbersize: 2019-01-17T11:00:48Z DEBUG 209715200 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:00:48Z DEBUG dc=example,dc=com 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-localssf: 2019-01-17T11:00:48Z DEBUG 71 2019-01-17T11:00:48Z DEBUG nsslapd-sizelimit: 2019-01-17T11:00:48Z DEBUG 2000 2019-01-17T11:00:48Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:00:48Z DEBUG dc=local 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:00:48Z DEBUG 2097152 2019-01-17T11:00:48Z DEBUG passwordLockoutDuration: 2019-01-17T11:00:48Z DEBUG 3600 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-port: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:00:48Z DEBUG cn=schema 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG cn=monitor 2019-01-17T11:00:48Z DEBUG cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-rootpw: 2019-01-17T11:00:48Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:00:48Z DEBUG 300000 2019-01-17T11:00:48Z DEBUG nsslapd-workingdir: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-rundir: 2019-01-17T11:00:48Z DEBUG /var/run/dirsrv 2019-01-17T11:00:48Z DEBUG nsslapd-schemareplace: 2019-01-17T11:00:48Z DEBUG replication-only 2019-01-17T11:00:48Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:00:48Z DEBUG 16384 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:00:48Z DEBUG 10000 2019-01-17T11:00:48Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordMinDigits: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG passwordStorageScheme: 2019-01-17T11:00:48Z DEBUG SSHA512 2019-01-17T11:00:48Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG [] 2019-01-17T11:00:48Z DEBUG Updated 0 2019-01-17T11:00:48Z DEBUG Done 2019-01-17T11:00:48Z DEBUG New entry: cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG nsContainer 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG retrieve certificate 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG nsContainer 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG retrieve certificate 2019-01-17T11:00:48Z ERROR Parent DN of cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=request certificate,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=request certificate,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG nsContainer 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG request certificate 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=request certificate,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG nsContainer 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG request certificate 2019-01-17T11:00:48Z ERROR Parent DN of cn=request certificate,cn=virtual operations,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=request certificate different host,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=request certificate different host,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG nsContainer 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG request certificate different host 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=request certificate different host,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG nsContainer 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG request certificate different host 2019-01-17T11:00:48Z ERROR Parent DN of cn=request certificate different host,cn=virtual operations,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=certificate status,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=certificate status,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG nsContainer 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG certificate status 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=certificate status,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG nsContainer 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG certificate status 2019-01-17T11:00:48Z ERROR Parent DN of cn=certificate status,cn=virtual operations,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=revoke certificate,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=revoke certificate,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG nsContainer 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG revoke certificate 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=revoke certificate,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG nsContainer 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG revoke certificate 2019-01-17T11:00:48Z ERROR Parent DN of cn=revoke certificate,cn=virtual operations,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG nsContainer 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG certificate remove hold 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG nsContainer 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG certificate remove hold 2019-01-17T11:00:48Z ERROR Parent DN of cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG nsContainer 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG request certificate ignore caacl 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG nsContainer 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG request certificate ignore caacl 2019-01-17T11:00:48Z ERROR Parent DN of cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG ipapermission 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Request Certificate ignoring CA ACLs 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG ipapermission 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Request Certificate ignoring CA ACLs 2019-01-17T11:00:48Z ERROR Parent DN of cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: dc=local 2019-01-17T11:00:48Z DEBUG add: '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local";)' to aci, current value [] 2019-01-17T11:00:48Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: dc=local 2019-01-17T11:00:48Z DEBUG aci: 2019-01-17T11:00:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z ERROR Add failure missing required attribute "objectclass" 2019-01-17T11:00:48Z DEBUG New entry: cn=RBAC Readers,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=RBAC Readers,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG RBAC Readers 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG Read roles, privileges, permissions and ACIs 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=RBAC Readers,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG RBAC Readers 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG Read roles, privileges, permissions and ACIs 2019-01-17T11:00:48Z ERROR Parent DN of cn=RBAC Readers,cn=privileges,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=Password Policy Readers,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=Password Policy Readers,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Password Policy Readers 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG Read password policies 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=Password Policy Readers,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Password Policy Readers 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG Read password policies 2019-01-17T11:00:48Z ERROR Parent DN of cn=Password Policy Readers,cn=privileges,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=Kerberos Ticket Policy Readers,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=Kerberos Ticket Policy Readers,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Kerberos Ticket Policy Readers 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG Read global and per-user Kerberos ticket policy 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=Kerberos Ticket Policy Readers,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Kerberos Ticket Policy Readers 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG Read global and per-user Kerberos ticket policy 2019-01-17T11:00:48Z ERROR Parent DN of cn=Kerberos Ticket Policy Readers,cn=privileges,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=Automember Readers,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=Automember Readers,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Automember Readers 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG Read Automember definitions 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=Automember Readers,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Automember Readers 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG Read Automember definitions 2019-01-17T11:00:48Z ERROR Parent DN of cn=Automember Readers,cn=privileges,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=IPA Masters Readers,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=IPA Masters Readers,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG IPA Masters Readers 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG Read list of IPA masters 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=IPA Masters Readers,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG IPA Masters Readers 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG Read list of IPA masters 2019-01-17T11:00:48Z ERROR Parent DN of cn=IPA Masters Readers,cn=privileges,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG remove: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) userdn = "ldap:///fqdn=centos75.local,cn=computers,cn=accounts,dc=local";)' from aci, current value [] 2019-01-17T11:00:48Z DEBUG remove: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) userdn = "ldap:///fqdn=centos75.local,cn=computers,cn=accounts,dc=local";)' not in aci 2019-01-17T11:00:48Z DEBUG remove: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) userdn = "ldap:///fqdn=centos75.local,cn=computers,cn=accounts,dc=local";)' from aci, current value [] 2019-01-17T11:00:48Z DEBUG remove: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) userdn = "ldap:///fqdn=centos75.local,cn=computers,cn=accounts,dc=local";)' not in aci 2019-01-17T11:00:48Z DEBUG add: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)' to aci, current value [] 2019-01-17T11:00:48Z DEBUG add: updated value [u'(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)'] 2019-01-17T11:00:48Z DEBUG add: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)' to aci, current value [u'(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)'] 2019-01-17T11:00:48Z DEBUG add: updated value [u'(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)'] 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG aci: 2019-01-17T11:00:48Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";) 2019-01-17T11:00:48Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";) 2019-01-17T11:00:48Z ERROR Parent DN of cn=masters,cn=ipa,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=PassSync Service,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=PassSync Service,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG PassSync Service 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG PassSync Service 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=PassSync Service,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG PassSync Service 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG PassSync Service 2019-01-17T11:00:48Z ERROR Parent DN of cn=PassSync Service,cn=privileges,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG ipapermission 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG ipapermissiontype: 2019-01-17T11:00:48Z DEBUG SYSTEM 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Read PassSync Managers Configuration 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG ipapermission 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG ipapermissiontype: 2019-01-17T11:00:48Z DEBUG SYSTEM 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Read PassSync Managers Configuration 2019-01-17T11:00:48Z ERROR Parent DN of cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG Updating existing entry: cn=config 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-betype: 2019-01-17T11:00:48Z DEBUG ldbm database 2019-01-17T11:00:48Z DEBUG nsslapd-nagle: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-referralmode: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:00:48Z DEBUG 64 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 500 2019-01-17T11:00:48Z DEBUG passwordMinAlphas: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-readonly: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordLegacyPolicy: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:00:48Z DEBUG allowed 2019-01-17T11:00:48Z DEBUG passwordMinUppers: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-plugin: 2019-01-17T11:00:48Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:00:48Z DEBUG 2097152 2019-01-17T11:00:48Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:00:48Z DEBUG 20971520 2019-01-17T11:00:48Z DEBUG nsslapd-timelimit: 2019-01-17T11:00:48Z DEBUG 3600 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordMinTokenLength: 2019-01-17T11:00:48Z DEBUG 3 2019-01-17T11:00:48Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:00:48Z DEBUG -10 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG week 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG passwordMinAge: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG week 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:00:48Z DEBUG 60 2019-01-17T11:00:48Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:00:48Z DEBUG 1024 2019-01-17T11:00:48Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordInHistory: 2019-01-17T11:00:48Z DEBUG 6 2019-01-17T11:00:48Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-conntablesize: 2019-01-17T11:00:48Z DEBUG 16384 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG nsslapd-saslpath: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG passwordMaxAge: 2019-01-17T11:00:48Z DEBUG 8640000 2019-01-17T11:00:48Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:00:48Z DEBUG gidNumber 2019-01-17T11:00:48Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG day 2019-01-17T11:00:48Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-csnlogging: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-tmpdir: 2019-01-17T11:00:48Z DEBUG /tmp 2019-01-17T11:00:48Z DEBUG passwordResetFailureCount: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-counters: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-svrtab: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG nsslapd-minssf: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-schemadir: 2019-01-17T11:00:48Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:00:48Z DEBUG nsslapd-localuser: 2019-01-17T11:00:48Z DEBUG dirsrv 2019-01-17T11:00:48Z DEBUG nsslapd-security: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordChange: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-port 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:00:48Z DEBUG passwordMaxFailure: 2019-01-17T11:00:48Z DEBUG 3 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:00:48Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:00:48Z DEBUG 128 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:00:48Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-rootdn: 2019-01-17T11:00:48Z DEBUG cn=Directory Manager 2019-01-17T11:00:48Z DEBUG nsslapd-ldifdir: 2019-01-17T11:00:48Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:00:48Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG passwordMustChange: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordExp: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-logging-backend: 2019-01-17T11:00:48Z DEBUG dirsrv-log 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:48Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG aci: 2019-01-17T11:00:48Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:00:48Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:00:48Z DEBUG cn=Directory Manager 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordMinLength: 2019-01-17T11:00:48Z DEBUG 8 2019-01-17T11:00:48Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-idletimeout: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:00:48Z DEBUG -10 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG week 2019-01-17T11:00:48Z DEBUG nsslapd-securePort: 2019-01-17T11:00:48Z DEBUG 636 2019-01-17T11:00:48Z DEBUG nsslapd-snmp-index: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG config 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG extensibleObject 2019-01-17T11:00:48Z DEBUG nsslapdConfig 2019-01-17T11:00:48Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordSendExpiringTime: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-hash-filters: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:00:48Z DEBUG next 2019-01-17T11:00:48Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:00:48Z DEBUG -10 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-listenhost: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordCheckSyntax: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordGraceLimit: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG passwordWarning: 2019-01-17T11:00:48Z DEBUG 86400 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-instancedir: 2019-01-17T11:00:48Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-config: 2019-01-17T11:00:48Z DEBUG cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-versionstring: 2019-01-17T11:00:48Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:00:48Z DEBUG 256 2019-01-17T11:00:48Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:00:48Z DEBUG 2097152 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:00:48Z DEBUG SSHA512 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG passwordLockout: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-lockdir: 2019-01-17T11:00:48Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-certdir: 2019-01-17T11:00:48Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 10 2019-01-17T11:00:48Z DEBUG nsslapd-backendconfig: 2019-01-17T11:00:48Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-threadnumber: 2019-01-17T11:00:48Z DEBUG 24 2019-01-17T11:00:48Z DEBUG nsslapd-schemamod: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-localhost: 2019-01-17T11:00:48Z DEBUG centos75.local 2019-01-17T11:00:48Z DEBUG nsslapd-bakdir: 2019-01-17T11:00:48Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:00:48Z DEBUG passwordMin8bit: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:00:48Z DEBUG uidNumber 2019-01-17T11:00:48Z DEBUG nsslapd-validate-cert: 2019-01-17T11:00:48Z DEBUG warn 2019-01-17T11:00:48Z DEBUG passwordMinCategories: 2019-01-17T11:00:48Z DEBUG 3 2019-01-17T11:00:48Z DEBUG passwordMinLowers: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordAdminDN: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordMinSpecials: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-lastmod: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:00:48Z DEBUG 40 2019-01-17T11:00:48Z DEBUG passwordMaxRepeats: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:00:48Z DEBUG -1 2019-01-17T11:00:48Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:00:48Z DEBUG none 2019-01-17T11:00:48Z DEBUG nsslapd-result-tweak: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG passwordUnlock: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-schemacheck: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-maxbersize: 2019-01-17T11:00:48Z DEBUG 209715200 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:00:48Z DEBUG dc=example,dc=com 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-localssf: 2019-01-17T11:00:48Z DEBUG 71 2019-01-17T11:00:48Z DEBUG nsslapd-sizelimit: 2019-01-17T11:00:48Z DEBUG 2000 2019-01-17T11:00:48Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:00:48Z DEBUG dc=local 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:00:48Z DEBUG 2097152 2019-01-17T11:00:48Z DEBUG passwordLockoutDuration: 2019-01-17T11:00:48Z DEBUG 3600 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-port: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:00:48Z DEBUG cn=schema 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG cn=monitor 2019-01-17T11:00:48Z DEBUG cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-rootpw: 2019-01-17T11:00:48Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:00:48Z DEBUG 300000 2019-01-17T11:00:48Z DEBUG nsslapd-workingdir: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-rundir: 2019-01-17T11:00:48Z DEBUG /var/run/dirsrv 2019-01-17T11:00:48Z DEBUG nsslapd-schemareplace: 2019-01-17T11:00:48Z DEBUG replication-only 2019-01-17T11:00:48Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:00:48Z DEBUG 16384 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:00:48Z DEBUG 10000 2019-01-17T11:00:48Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordMinDigits: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG passwordStorageScheme: 2019-01-17T11:00:48Z DEBUG SSHA512 2019-01-17T11:00:48Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG add: '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)' to aci, current value [u'(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";)', u'(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:00:48Z DEBUG add: updated value [u'(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";)', u'(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-betype: 2019-01-17T11:00:48Z DEBUG ldbm database 2019-01-17T11:00:48Z DEBUG nsslapd-nagle: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-referralmode: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:00:48Z DEBUG 64 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 500 2019-01-17T11:00:48Z DEBUG passwordMinAlphas: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-readonly: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordLegacyPolicy: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:00:48Z DEBUG allowed 2019-01-17T11:00:48Z DEBUG passwordMinUppers: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-plugin: 2019-01-17T11:00:48Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:00:48Z DEBUG 2097152 2019-01-17T11:00:48Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:00:48Z DEBUG 20971520 2019-01-17T11:00:48Z DEBUG nsslapd-timelimit: 2019-01-17T11:00:48Z DEBUG 3600 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordMinTokenLength: 2019-01-17T11:00:48Z DEBUG 3 2019-01-17T11:00:48Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:00:48Z DEBUG -10 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG week 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG passwordMinAge: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG week 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:00:48Z DEBUG 60 2019-01-17T11:00:48Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:00:48Z DEBUG 1024 2019-01-17T11:00:48Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordInHistory: 2019-01-17T11:00:48Z DEBUG 6 2019-01-17T11:00:48Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-conntablesize: 2019-01-17T11:00:48Z DEBUG 16384 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG nsslapd-saslpath: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG passwordMaxAge: 2019-01-17T11:00:48Z DEBUG 8640000 2019-01-17T11:00:48Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:00:48Z DEBUG gidNumber 2019-01-17T11:00:48Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG day 2019-01-17T11:00:48Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-csnlogging: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-tmpdir: 2019-01-17T11:00:48Z DEBUG /tmp 2019-01-17T11:00:48Z DEBUG passwordResetFailureCount: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-counters: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-svrtab: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG nsslapd-minssf: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-schemadir: 2019-01-17T11:00:48Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:00:48Z DEBUG nsslapd-localuser: 2019-01-17T11:00:48Z DEBUG dirsrv 2019-01-17T11:00:48Z DEBUG nsslapd-security: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordChange: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-port 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:00:48Z DEBUG passwordMaxFailure: 2019-01-17T11:00:48Z DEBUG 3 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:00:48Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:00:48Z DEBUG 128 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:00:48Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-rootdn: 2019-01-17T11:00:48Z DEBUG cn=Directory Manager 2019-01-17T11:00:48Z DEBUG nsslapd-ldifdir: 2019-01-17T11:00:48Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:00:48Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG passwordMustChange: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordExp: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-logging-backend: 2019-01-17T11:00:48Z DEBUG dirsrv-log 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:48Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG aci: 2019-01-17T11:00:48Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:00:48Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:00:48Z DEBUG cn=Directory Manager 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordMinLength: 2019-01-17T11:00:48Z DEBUG 8 2019-01-17T11:00:48Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-idletimeout: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:00:48Z DEBUG -10 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG week 2019-01-17T11:00:48Z DEBUG nsslapd-securePort: 2019-01-17T11:00:48Z DEBUG 636 2019-01-17T11:00:48Z DEBUG nsslapd-snmp-index: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG config 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG extensibleObject 2019-01-17T11:00:48Z DEBUG nsslapdConfig 2019-01-17T11:00:48Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordSendExpiringTime: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-hash-filters: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:00:48Z DEBUG next 2019-01-17T11:00:48Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:00:48Z DEBUG -10 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-listenhost: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordCheckSyntax: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordGraceLimit: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG passwordWarning: 2019-01-17T11:00:48Z DEBUG 86400 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-instancedir: 2019-01-17T11:00:48Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-config: 2019-01-17T11:00:48Z DEBUG cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-versionstring: 2019-01-17T11:00:48Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:00:48Z DEBUG 256 2019-01-17T11:00:48Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:00:48Z DEBUG 2097152 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:00:48Z DEBUG SSHA512 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG passwordLockout: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-lockdir: 2019-01-17T11:00:48Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-certdir: 2019-01-17T11:00:48Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 10 2019-01-17T11:00:48Z DEBUG nsslapd-backendconfig: 2019-01-17T11:00:48Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-threadnumber: 2019-01-17T11:00:48Z DEBUG 24 2019-01-17T11:00:48Z DEBUG nsslapd-schemamod: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-localhost: 2019-01-17T11:00:48Z DEBUG centos75.local 2019-01-17T11:00:48Z DEBUG nsslapd-bakdir: 2019-01-17T11:00:48Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:00:48Z DEBUG passwordMin8bit: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:00:48Z DEBUG uidNumber 2019-01-17T11:00:48Z DEBUG nsslapd-validate-cert: 2019-01-17T11:00:48Z DEBUG warn 2019-01-17T11:00:48Z DEBUG passwordMinCategories: 2019-01-17T11:00:48Z DEBUG 3 2019-01-17T11:00:48Z DEBUG passwordMinLowers: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordAdminDN: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordMinSpecials: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-lastmod: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:00:48Z DEBUG 40 2019-01-17T11:00:48Z DEBUG passwordMaxRepeats: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:00:48Z DEBUG -1 2019-01-17T11:00:48Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:00:48Z DEBUG none 2019-01-17T11:00:48Z DEBUG nsslapd-result-tweak: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG passwordUnlock: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-schemacheck: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-maxbersize: 2019-01-17T11:00:48Z DEBUG 209715200 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:00:48Z DEBUG dc=example,dc=com 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-localssf: 2019-01-17T11:00:48Z DEBUG 71 2019-01-17T11:00:48Z DEBUG nsslapd-sizelimit: 2019-01-17T11:00:48Z DEBUG 2000 2019-01-17T11:00:48Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:00:48Z DEBUG dc=local 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:00:48Z DEBUG 2097152 2019-01-17T11:00:48Z DEBUG passwordLockoutDuration: 2019-01-17T11:00:48Z DEBUG 3600 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-port: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:00:48Z DEBUG cn=schema 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG cn=monitor 2019-01-17T11:00:48Z DEBUG cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-rootpw: 2019-01-17T11:00:48Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:00:48Z DEBUG 300000 2019-01-17T11:00:48Z DEBUG nsslapd-workingdir: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-rundir: 2019-01-17T11:00:48Z DEBUG /var/run/dirsrv 2019-01-17T11:00:48Z DEBUG nsslapd-schemareplace: 2019-01-17T11:00:48Z DEBUG replication-only 2019-01-17T11:00:48Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:00:48Z DEBUG 16384 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:00:48Z DEBUG 10000 2019-01-17T11:00:48Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordMinDigits: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG passwordStorageScheme: 2019-01-17T11:00:48Z DEBUG SSHA512 2019-01-17T11:00:48Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG [] 2019-01-17T11:00:48Z DEBUG Updated 0 2019-01-17T11:00:48Z DEBUG Done 2019-01-17T11:00:48Z DEBUG New entry: cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG ipapermission 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG ipapermissiontype: 2019-01-17T11:00:48Z DEBUG SYSTEM 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Modify PassSync Managers Configuration 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG ipapermission 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG ipapermissiontype: 2019-01-17T11:00:48Z DEBUG SYSTEM 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Modify PassSync Managers Configuration 2019-01-17T11:00:48Z ERROR Parent DN of cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG Updating existing entry: cn=config 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-betype: 2019-01-17T11:00:48Z DEBUG ldbm database 2019-01-17T11:00:48Z DEBUG nsslapd-nagle: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-referralmode: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:00:48Z DEBUG 64 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 500 2019-01-17T11:00:48Z DEBUG passwordMinAlphas: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-readonly: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordLegacyPolicy: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:00:48Z DEBUG allowed 2019-01-17T11:00:48Z DEBUG passwordMinUppers: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-plugin: 2019-01-17T11:00:48Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:00:48Z DEBUG 2097152 2019-01-17T11:00:48Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:00:48Z DEBUG 20971520 2019-01-17T11:00:48Z DEBUG nsslapd-timelimit: 2019-01-17T11:00:48Z DEBUG 3600 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordMinTokenLength: 2019-01-17T11:00:48Z DEBUG 3 2019-01-17T11:00:48Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:00:48Z DEBUG -10 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG week 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG passwordMinAge: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG week 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:00:48Z DEBUG 60 2019-01-17T11:00:48Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:00:48Z DEBUG 1024 2019-01-17T11:00:48Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordInHistory: 2019-01-17T11:00:48Z DEBUG 6 2019-01-17T11:00:48Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-conntablesize: 2019-01-17T11:00:48Z DEBUG 16384 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG nsslapd-saslpath: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG passwordMaxAge: 2019-01-17T11:00:48Z DEBUG 8640000 2019-01-17T11:00:48Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:00:48Z DEBUG gidNumber 2019-01-17T11:00:48Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG day 2019-01-17T11:00:48Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-csnlogging: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-tmpdir: 2019-01-17T11:00:48Z DEBUG /tmp 2019-01-17T11:00:48Z DEBUG passwordResetFailureCount: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-counters: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-svrtab: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG nsslapd-minssf: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-schemadir: 2019-01-17T11:00:48Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:00:48Z DEBUG nsslapd-localuser: 2019-01-17T11:00:48Z DEBUG dirsrv 2019-01-17T11:00:48Z DEBUG nsslapd-security: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordChange: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-port 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:00:48Z DEBUG passwordMaxFailure: 2019-01-17T11:00:48Z DEBUG 3 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:00:48Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:00:48Z DEBUG 128 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:00:48Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-rootdn: 2019-01-17T11:00:48Z DEBUG cn=Directory Manager 2019-01-17T11:00:48Z DEBUG nsslapd-ldifdir: 2019-01-17T11:00:48Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:00:48Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG passwordMustChange: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordExp: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-logging-backend: 2019-01-17T11:00:48Z DEBUG dirsrv-log 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:48Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG aci: 2019-01-17T11:00:48Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:00:48Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:00:48Z DEBUG cn=Directory Manager 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordMinLength: 2019-01-17T11:00:48Z DEBUG 8 2019-01-17T11:00:48Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-idletimeout: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:00:48Z DEBUG -10 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG week 2019-01-17T11:00:48Z DEBUG nsslapd-securePort: 2019-01-17T11:00:48Z DEBUG 636 2019-01-17T11:00:48Z DEBUG nsslapd-snmp-index: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG config 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG extensibleObject 2019-01-17T11:00:48Z DEBUG nsslapdConfig 2019-01-17T11:00:48Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordSendExpiringTime: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-hash-filters: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:00:48Z DEBUG next 2019-01-17T11:00:48Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:00:48Z DEBUG -10 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-listenhost: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordCheckSyntax: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordGraceLimit: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG passwordWarning: 2019-01-17T11:00:48Z DEBUG 86400 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-instancedir: 2019-01-17T11:00:48Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-config: 2019-01-17T11:00:48Z DEBUG cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-versionstring: 2019-01-17T11:00:48Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:00:48Z DEBUG 256 2019-01-17T11:00:48Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:00:48Z DEBUG 2097152 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:00:48Z DEBUG SSHA512 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG passwordLockout: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-lockdir: 2019-01-17T11:00:48Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-certdir: 2019-01-17T11:00:48Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 10 2019-01-17T11:00:48Z DEBUG nsslapd-backendconfig: 2019-01-17T11:00:48Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-threadnumber: 2019-01-17T11:00:48Z DEBUG 24 2019-01-17T11:00:48Z DEBUG nsslapd-schemamod: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-localhost: 2019-01-17T11:00:48Z DEBUG centos75.local 2019-01-17T11:00:48Z DEBUG nsslapd-bakdir: 2019-01-17T11:00:48Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:00:48Z DEBUG passwordMin8bit: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:00:48Z DEBUG uidNumber 2019-01-17T11:00:48Z DEBUG nsslapd-validate-cert: 2019-01-17T11:00:48Z DEBUG warn 2019-01-17T11:00:48Z DEBUG passwordMinCategories: 2019-01-17T11:00:48Z DEBUG 3 2019-01-17T11:00:48Z DEBUG passwordMinLowers: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordAdminDN: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordMinSpecials: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-lastmod: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:00:48Z DEBUG 40 2019-01-17T11:00:48Z DEBUG passwordMaxRepeats: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:00:48Z DEBUG -1 2019-01-17T11:00:48Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:00:48Z DEBUG none 2019-01-17T11:00:48Z DEBUG nsslapd-result-tweak: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG passwordUnlock: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-schemacheck: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-maxbersize: 2019-01-17T11:00:48Z DEBUG 209715200 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:00:48Z DEBUG dc=example,dc=com 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-localssf: 2019-01-17T11:00:48Z DEBUG 71 2019-01-17T11:00:48Z DEBUG nsslapd-sizelimit: 2019-01-17T11:00:48Z DEBUG 2000 2019-01-17T11:00:48Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:00:48Z DEBUG dc=local 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:00:48Z DEBUG 2097152 2019-01-17T11:00:48Z DEBUG passwordLockoutDuration: 2019-01-17T11:00:48Z DEBUG 3600 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-port: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:00:48Z DEBUG cn=schema 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG cn=monitor 2019-01-17T11:00:48Z DEBUG cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-rootpw: 2019-01-17T11:00:48Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:00:48Z DEBUG 300000 2019-01-17T11:00:48Z DEBUG nsslapd-workingdir: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-rundir: 2019-01-17T11:00:48Z DEBUG /var/run/dirsrv 2019-01-17T11:00:48Z DEBUG nsslapd-schemareplace: 2019-01-17T11:00:48Z DEBUG replication-only 2019-01-17T11:00:48Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:00:48Z DEBUG 16384 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:00:48Z DEBUG 10000 2019-01-17T11:00:48Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordMinDigits: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG passwordStorageScheme: 2019-01-17T11:00:48Z DEBUG SSHA512 2019-01-17T11:00:48Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG add: '(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)' to aci, current value [u'(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";)', u'(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:00:48Z DEBUG add: updated value [u'(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";)', u'(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-betype: 2019-01-17T11:00:48Z DEBUG ldbm database 2019-01-17T11:00:48Z DEBUG nsslapd-nagle: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-referralmode: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:00:48Z DEBUG 64 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 500 2019-01-17T11:00:48Z DEBUG passwordMinAlphas: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-readonly: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordLegacyPolicy: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:00:48Z DEBUG allowed 2019-01-17T11:00:48Z DEBUG passwordMinUppers: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-plugin: 2019-01-17T11:00:48Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:00:48Z DEBUG 2097152 2019-01-17T11:00:48Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:00:48Z DEBUG 20971520 2019-01-17T11:00:48Z DEBUG nsslapd-timelimit: 2019-01-17T11:00:48Z DEBUG 3600 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordMinTokenLength: 2019-01-17T11:00:48Z DEBUG 3 2019-01-17T11:00:48Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:00:48Z DEBUG -10 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG week 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG passwordMinAge: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG week 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:00:48Z DEBUG 60 2019-01-17T11:00:48Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:00:48Z DEBUG 1024 2019-01-17T11:00:48Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordInHistory: 2019-01-17T11:00:48Z DEBUG 6 2019-01-17T11:00:48Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-conntablesize: 2019-01-17T11:00:48Z DEBUG 16384 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG nsslapd-saslpath: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG passwordMaxAge: 2019-01-17T11:00:48Z DEBUG 8640000 2019-01-17T11:00:48Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:00:48Z DEBUG gidNumber 2019-01-17T11:00:48Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG day 2019-01-17T11:00:48Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-csnlogging: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-tmpdir: 2019-01-17T11:00:48Z DEBUG /tmp 2019-01-17T11:00:48Z DEBUG passwordResetFailureCount: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-counters: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-svrtab: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG nsslapd-minssf: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-schemadir: 2019-01-17T11:00:48Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:00:48Z DEBUG nsslapd-localuser: 2019-01-17T11:00:48Z DEBUG dirsrv 2019-01-17T11:00:48Z DEBUG nsslapd-security: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordChange: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-port 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:00:48Z DEBUG passwordMaxFailure: 2019-01-17T11:00:48Z DEBUG 3 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:00:48Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:00:48Z DEBUG 128 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:00:48Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-rootdn: 2019-01-17T11:00:48Z DEBUG cn=Directory Manager 2019-01-17T11:00:48Z DEBUG nsslapd-ldifdir: 2019-01-17T11:00:48Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:00:48Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG passwordMustChange: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordExp: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-logging-backend: 2019-01-17T11:00:48Z DEBUG dirsrv-log 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:48Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG aci: 2019-01-17T11:00:48Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:00:48Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:00:48Z DEBUG cn=Directory Manager 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordMinLength: 2019-01-17T11:00:48Z DEBUG 8 2019-01-17T11:00:48Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-idletimeout: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:00:48Z DEBUG -10 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG week 2019-01-17T11:00:48Z DEBUG nsslapd-securePort: 2019-01-17T11:00:48Z DEBUG 636 2019-01-17T11:00:48Z DEBUG nsslapd-snmp-index: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG config 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG extensibleObject 2019-01-17T11:00:48Z DEBUG nsslapdConfig 2019-01-17T11:00:48Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordSendExpiringTime: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-hash-filters: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:00:48Z DEBUG next 2019-01-17T11:00:48Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:00:48Z DEBUG -10 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-listenhost: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordCheckSyntax: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordGraceLimit: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG passwordWarning: 2019-01-17T11:00:48Z DEBUG 86400 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-instancedir: 2019-01-17T11:00:48Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-config: 2019-01-17T11:00:48Z DEBUG cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-versionstring: 2019-01-17T11:00:48Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:00:48Z DEBUG 256 2019-01-17T11:00:48Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:00:48Z DEBUG 2097152 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:00:48Z DEBUG SSHA512 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG passwordLockout: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-lockdir: 2019-01-17T11:00:48Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-certdir: 2019-01-17T11:00:48Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 10 2019-01-17T11:00:48Z DEBUG nsslapd-backendconfig: 2019-01-17T11:00:48Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-threadnumber: 2019-01-17T11:00:48Z DEBUG 24 2019-01-17T11:00:48Z DEBUG nsslapd-schemamod: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-localhost: 2019-01-17T11:00:48Z DEBUG centos75.local 2019-01-17T11:00:48Z DEBUG nsslapd-bakdir: 2019-01-17T11:00:48Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:00:48Z DEBUG passwordMin8bit: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:00:48Z DEBUG uidNumber 2019-01-17T11:00:48Z DEBUG nsslapd-validate-cert: 2019-01-17T11:00:48Z DEBUG warn 2019-01-17T11:00:48Z DEBUG passwordMinCategories: 2019-01-17T11:00:48Z DEBUG 3 2019-01-17T11:00:48Z DEBUG passwordMinLowers: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordAdminDN: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordMinSpecials: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-lastmod: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:00:48Z DEBUG 40 2019-01-17T11:00:48Z DEBUG passwordMaxRepeats: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:00:48Z DEBUG -1 2019-01-17T11:00:48Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:00:48Z DEBUG none 2019-01-17T11:00:48Z DEBUG nsslapd-result-tweak: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG passwordUnlock: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-schemacheck: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-maxbersize: 2019-01-17T11:00:48Z DEBUG 209715200 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:00:48Z DEBUG dc=example,dc=com 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-localssf: 2019-01-17T11:00:48Z DEBUG 71 2019-01-17T11:00:48Z DEBUG nsslapd-sizelimit: 2019-01-17T11:00:48Z DEBUG 2000 2019-01-17T11:00:48Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:00:48Z DEBUG dc=local 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:00:48Z DEBUG 2097152 2019-01-17T11:00:48Z DEBUG passwordLockoutDuration: 2019-01-17T11:00:48Z DEBUG 3600 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-port: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:00:48Z DEBUG cn=schema 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG cn=monitor 2019-01-17T11:00:48Z DEBUG cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-rootpw: 2019-01-17T11:00:48Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:00:48Z DEBUG 300000 2019-01-17T11:00:48Z DEBUG nsslapd-workingdir: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-rundir: 2019-01-17T11:00:48Z DEBUG /var/run/dirsrv 2019-01-17T11:00:48Z DEBUG nsslapd-schemareplace: 2019-01-17T11:00:48Z DEBUG replication-only 2019-01-17T11:00:48Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:00:48Z DEBUG 16384 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:00:48Z DEBUG 10000 2019-01-17T11:00:48Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordMinDigits: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG passwordStorageScheme: 2019-01-17T11:00:48Z DEBUG SSHA512 2019-01-17T11:00:48Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG [] 2019-01-17T11:00:48Z DEBUG Updated 0 2019-01-17T11:00:48Z DEBUG Done 2019-01-17T11:00:48Z DEBUG New entry: cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG ipapermission 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG ipapermissiontype: 2019-01-17T11:00:48Z DEBUG SYSTEM 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Read LDBM Database Configuration 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG ipapermission 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG ipapermissiontype: 2019-01-17T11:00:48Z DEBUG SYSTEM 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Read LDBM Database Configuration 2019-01-17T11:00:48Z ERROR Parent DN of cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG Updating existing entry: cn=config 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-betype: 2019-01-17T11:00:48Z DEBUG ldbm database 2019-01-17T11:00:48Z DEBUG nsslapd-nagle: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-referralmode: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:00:48Z DEBUG 64 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 500 2019-01-17T11:00:48Z DEBUG passwordMinAlphas: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-readonly: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordLegacyPolicy: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:00:48Z DEBUG allowed 2019-01-17T11:00:48Z DEBUG passwordMinUppers: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-plugin: 2019-01-17T11:00:48Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:00:48Z DEBUG 2097152 2019-01-17T11:00:48Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:00:48Z DEBUG 20971520 2019-01-17T11:00:48Z DEBUG nsslapd-timelimit: 2019-01-17T11:00:48Z DEBUG 3600 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordMinTokenLength: 2019-01-17T11:00:48Z DEBUG 3 2019-01-17T11:00:48Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:00:48Z DEBUG -10 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG week 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG passwordMinAge: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG week 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:00:48Z DEBUG 60 2019-01-17T11:00:48Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:00:48Z DEBUG 1024 2019-01-17T11:00:48Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordInHistory: 2019-01-17T11:00:48Z DEBUG 6 2019-01-17T11:00:48Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-conntablesize: 2019-01-17T11:00:48Z DEBUG 16384 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG nsslapd-saslpath: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG passwordMaxAge: 2019-01-17T11:00:48Z DEBUG 8640000 2019-01-17T11:00:48Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:00:48Z DEBUG gidNumber 2019-01-17T11:00:48Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG day 2019-01-17T11:00:48Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-csnlogging: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-tmpdir: 2019-01-17T11:00:48Z DEBUG /tmp 2019-01-17T11:00:48Z DEBUG passwordResetFailureCount: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-counters: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-svrtab: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG nsslapd-minssf: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-schemadir: 2019-01-17T11:00:48Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:00:48Z DEBUG nsslapd-localuser: 2019-01-17T11:00:48Z DEBUG dirsrv 2019-01-17T11:00:48Z DEBUG nsslapd-security: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordChange: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-port 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:00:48Z DEBUG passwordMaxFailure: 2019-01-17T11:00:48Z DEBUG 3 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:00:48Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:00:48Z DEBUG 128 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:00:48Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-rootdn: 2019-01-17T11:00:48Z DEBUG cn=Directory Manager 2019-01-17T11:00:48Z DEBUG nsslapd-ldifdir: 2019-01-17T11:00:48Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:00:48Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG passwordMustChange: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordExp: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-logging-backend: 2019-01-17T11:00:48Z DEBUG dirsrv-log 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:48Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG aci: 2019-01-17T11:00:48Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:00:48Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:00:48Z DEBUG cn=Directory Manager 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordMinLength: 2019-01-17T11:00:48Z DEBUG 8 2019-01-17T11:00:48Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-idletimeout: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:00:48Z DEBUG -10 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG week 2019-01-17T11:00:48Z DEBUG nsslapd-securePort: 2019-01-17T11:00:48Z DEBUG 636 2019-01-17T11:00:48Z DEBUG nsslapd-snmp-index: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG config 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG extensibleObject 2019-01-17T11:00:48Z DEBUG nsslapdConfig 2019-01-17T11:00:48Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordSendExpiringTime: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-hash-filters: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:00:48Z DEBUG next 2019-01-17T11:00:48Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:00:48Z DEBUG -10 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-listenhost: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordCheckSyntax: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordGraceLimit: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG passwordWarning: 2019-01-17T11:00:48Z DEBUG 86400 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-instancedir: 2019-01-17T11:00:48Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-config: 2019-01-17T11:00:48Z DEBUG cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-versionstring: 2019-01-17T11:00:48Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:00:48Z DEBUG 256 2019-01-17T11:00:48Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:00:48Z DEBUG 2097152 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:00:48Z DEBUG SSHA512 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG passwordLockout: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-lockdir: 2019-01-17T11:00:48Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-certdir: 2019-01-17T11:00:48Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 10 2019-01-17T11:00:48Z DEBUG nsslapd-backendconfig: 2019-01-17T11:00:48Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-threadnumber: 2019-01-17T11:00:48Z DEBUG 24 2019-01-17T11:00:48Z DEBUG nsslapd-schemamod: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-localhost: 2019-01-17T11:00:48Z DEBUG centos75.local 2019-01-17T11:00:48Z DEBUG nsslapd-bakdir: 2019-01-17T11:00:48Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:00:48Z DEBUG passwordMin8bit: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:00:48Z DEBUG uidNumber 2019-01-17T11:00:48Z DEBUG nsslapd-validate-cert: 2019-01-17T11:00:48Z DEBUG warn 2019-01-17T11:00:48Z DEBUG passwordMinCategories: 2019-01-17T11:00:48Z DEBUG 3 2019-01-17T11:00:48Z DEBUG passwordMinLowers: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordAdminDN: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordMinSpecials: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-lastmod: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:00:48Z DEBUG 40 2019-01-17T11:00:48Z DEBUG passwordMaxRepeats: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:00:48Z DEBUG -1 2019-01-17T11:00:48Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:00:48Z DEBUG none 2019-01-17T11:00:48Z DEBUG nsslapd-result-tweak: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG passwordUnlock: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-schemacheck: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-maxbersize: 2019-01-17T11:00:48Z DEBUG 209715200 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:00:48Z DEBUG dc=example,dc=com 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-localssf: 2019-01-17T11:00:48Z DEBUG 71 2019-01-17T11:00:48Z DEBUG nsslapd-sizelimit: 2019-01-17T11:00:48Z DEBUG 2000 2019-01-17T11:00:48Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:00:48Z DEBUG dc=local 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:00:48Z DEBUG 2097152 2019-01-17T11:00:48Z DEBUG passwordLockoutDuration: 2019-01-17T11:00:48Z DEBUG 3600 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-port: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:00:48Z DEBUG cn=schema 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG cn=monitor 2019-01-17T11:00:48Z DEBUG cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-rootpw: 2019-01-17T11:00:48Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:00:48Z DEBUG 300000 2019-01-17T11:00:48Z DEBUG nsslapd-workingdir: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-rundir: 2019-01-17T11:00:48Z DEBUG /var/run/dirsrv 2019-01-17T11:00:48Z DEBUG nsslapd-schemareplace: 2019-01-17T11:00:48Z DEBUG replication-only 2019-01-17T11:00:48Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:00:48Z DEBUG 16384 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:00:48Z DEBUG 10000 2019-01-17T11:00:48Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordMinDigits: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG passwordStorageScheme: 2019-01-17T11:00:48Z DEBUG SSHA512 2019-01-17T11:00:48Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG add: '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";)' to aci, current value [u'(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";)', u'(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:00:48Z DEBUG add: updated value [u'(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-betype: 2019-01-17T11:00:48Z DEBUG ldbm database 2019-01-17T11:00:48Z DEBUG nsslapd-nagle: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-referralmode: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:00:48Z DEBUG 64 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 500 2019-01-17T11:00:48Z DEBUG passwordMinAlphas: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-readonly: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordLegacyPolicy: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:00:48Z DEBUG allowed 2019-01-17T11:00:48Z DEBUG passwordMinUppers: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-plugin: 2019-01-17T11:00:48Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:00:48Z DEBUG 2097152 2019-01-17T11:00:48Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:00:48Z DEBUG 20971520 2019-01-17T11:00:48Z DEBUG nsslapd-timelimit: 2019-01-17T11:00:48Z DEBUG 3600 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordMinTokenLength: 2019-01-17T11:00:48Z DEBUG 3 2019-01-17T11:00:48Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:00:48Z DEBUG -10 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG week 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG passwordMinAge: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG week 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:00:48Z DEBUG 60 2019-01-17T11:00:48Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:00:48Z DEBUG 1024 2019-01-17T11:00:48Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordInHistory: 2019-01-17T11:00:48Z DEBUG 6 2019-01-17T11:00:48Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-conntablesize: 2019-01-17T11:00:48Z DEBUG 16384 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG nsslapd-saslpath: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG passwordMaxAge: 2019-01-17T11:00:48Z DEBUG 8640000 2019-01-17T11:00:48Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:00:48Z DEBUG gidNumber 2019-01-17T11:00:48Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG day 2019-01-17T11:00:48Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-csnlogging: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-tmpdir: 2019-01-17T11:00:48Z DEBUG /tmp 2019-01-17T11:00:48Z DEBUG passwordResetFailureCount: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-counters: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-svrtab: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG nsslapd-minssf: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-schemadir: 2019-01-17T11:00:48Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:00:48Z DEBUG nsslapd-localuser: 2019-01-17T11:00:48Z DEBUG dirsrv 2019-01-17T11:00:48Z DEBUG nsslapd-security: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordChange: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-port 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:00:48Z DEBUG passwordMaxFailure: 2019-01-17T11:00:48Z DEBUG 3 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:00:48Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:00:48Z DEBUG 128 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:00:48Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-rootdn: 2019-01-17T11:00:48Z DEBUG cn=Directory Manager 2019-01-17T11:00:48Z DEBUG nsslapd-ldifdir: 2019-01-17T11:00:48Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:00:48Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG passwordMustChange: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordExp: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-logging-backend: 2019-01-17T11:00:48Z DEBUG dirsrv-log 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:48Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG aci: 2019-01-17T11:00:48Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:00:48Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:00:48Z DEBUG cn=Directory Manager 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordMinLength: 2019-01-17T11:00:48Z DEBUG 8 2019-01-17T11:00:48Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-idletimeout: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:00:48Z DEBUG -10 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG week 2019-01-17T11:00:48Z DEBUG nsslapd-securePort: 2019-01-17T11:00:48Z DEBUG 636 2019-01-17T11:00:48Z DEBUG nsslapd-snmp-index: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG config 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG extensibleObject 2019-01-17T11:00:48Z DEBUG nsslapdConfig 2019-01-17T11:00:48Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordSendExpiringTime: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-hash-filters: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:00:48Z DEBUG next 2019-01-17T11:00:48Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:00:48Z DEBUG -10 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-listenhost: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordCheckSyntax: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordGraceLimit: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG passwordWarning: 2019-01-17T11:00:48Z DEBUG 86400 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-instancedir: 2019-01-17T11:00:48Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-config: 2019-01-17T11:00:48Z DEBUG cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-versionstring: 2019-01-17T11:00:48Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:00:48Z DEBUG 256 2019-01-17T11:00:48Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:00:48Z DEBUG 2097152 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:00:48Z DEBUG SSHA512 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG passwordLockout: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-lockdir: 2019-01-17T11:00:48Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-certdir: 2019-01-17T11:00:48Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 10 2019-01-17T11:00:48Z DEBUG nsslapd-backendconfig: 2019-01-17T11:00:48Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-threadnumber: 2019-01-17T11:00:48Z DEBUG 24 2019-01-17T11:00:48Z DEBUG nsslapd-schemamod: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-localhost: 2019-01-17T11:00:48Z DEBUG centos75.local 2019-01-17T11:00:48Z DEBUG nsslapd-bakdir: 2019-01-17T11:00:48Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:00:48Z DEBUG passwordMin8bit: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:00:48Z DEBUG uidNumber 2019-01-17T11:00:48Z DEBUG nsslapd-validate-cert: 2019-01-17T11:00:48Z DEBUG warn 2019-01-17T11:00:48Z DEBUG passwordMinCategories: 2019-01-17T11:00:48Z DEBUG 3 2019-01-17T11:00:48Z DEBUG passwordMinLowers: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordAdminDN: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordMinSpecials: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-lastmod: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:00:48Z DEBUG 40 2019-01-17T11:00:48Z DEBUG passwordMaxRepeats: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:00:48Z DEBUG -1 2019-01-17T11:00:48Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:00:48Z DEBUG none 2019-01-17T11:00:48Z DEBUG nsslapd-result-tweak: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG passwordUnlock: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-schemacheck: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-maxbersize: 2019-01-17T11:00:48Z DEBUG 209715200 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:00:48Z DEBUG dc=example,dc=com 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-localssf: 2019-01-17T11:00:48Z DEBUG 71 2019-01-17T11:00:48Z DEBUG nsslapd-sizelimit: 2019-01-17T11:00:48Z DEBUG 2000 2019-01-17T11:00:48Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:00:48Z DEBUG dc=local 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:00:48Z DEBUG 2097152 2019-01-17T11:00:48Z DEBUG passwordLockoutDuration: 2019-01-17T11:00:48Z DEBUG 3600 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-port: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:00:48Z DEBUG cn=schema 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG cn=monitor 2019-01-17T11:00:48Z DEBUG cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-rootpw: 2019-01-17T11:00:48Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:00:48Z DEBUG 300000 2019-01-17T11:00:48Z DEBUG nsslapd-workingdir: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-rundir: 2019-01-17T11:00:48Z DEBUG /var/run/dirsrv 2019-01-17T11:00:48Z DEBUG nsslapd-schemareplace: 2019-01-17T11:00:48Z DEBUG replication-only 2019-01-17T11:00:48Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:00:48Z DEBUG 16384 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:00:48Z DEBUG 10000 2019-01-17T11:00:48Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordMinDigits: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG passwordStorageScheme: 2019-01-17T11:00:48Z DEBUG SSHA512 2019-01-17T11:00:48Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG [] 2019-01-17T11:00:48Z DEBUG Updated 0 2019-01-17T11:00:48Z DEBUG Done 2019-01-17T11:00:48Z DEBUG New entry: cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG ipapermission 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG ipapermissiontype: 2019-01-17T11:00:48Z DEBUG SYSTEM 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Add Configuration Sub-Entries 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG ipapermission 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG ipapermissiontype: 2019-01-17T11:00:48Z DEBUG SYSTEM 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Add Configuration Sub-Entries 2019-01-17T11:00:48Z ERROR Parent DN of cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG Updating existing entry: cn=config 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-betype: 2019-01-17T11:00:48Z DEBUG ldbm database 2019-01-17T11:00:48Z DEBUG nsslapd-nagle: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-referralmode: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:00:48Z DEBUG 64 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 500 2019-01-17T11:00:48Z DEBUG passwordMinAlphas: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-readonly: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordLegacyPolicy: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:00:48Z DEBUG allowed 2019-01-17T11:00:48Z DEBUG passwordMinUppers: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-plugin: 2019-01-17T11:00:48Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:00:48Z DEBUG 2097152 2019-01-17T11:00:48Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:00:48Z DEBUG 20971520 2019-01-17T11:00:48Z DEBUG nsslapd-timelimit: 2019-01-17T11:00:48Z DEBUG 3600 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordMinTokenLength: 2019-01-17T11:00:48Z DEBUG 3 2019-01-17T11:00:48Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:00:48Z DEBUG -10 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG week 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG passwordMinAge: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG week 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:00:48Z DEBUG 60 2019-01-17T11:00:48Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:00:48Z DEBUG 1024 2019-01-17T11:00:48Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordInHistory: 2019-01-17T11:00:48Z DEBUG 6 2019-01-17T11:00:48Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-conntablesize: 2019-01-17T11:00:48Z DEBUG 16384 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG nsslapd-saslpath: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG passwordMaxAge: 2019-01-17T11:00:48Z DEBUG 8640000 2019-01-17T11:00:48Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:00:48Z DEBUG gidNumber 2019-01-17T11:00:48Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG day 2019-01-17T11:00:48Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-csnlogging: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-tmpdir: 2019-01-17T11:00:48Z DEBUG /tmp 2019-01-17T11:00:48Z DEBUG passwordResetFailureCount: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-counters: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-svrtab: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG nsslapd-minssf: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-schemadir: 2019-01-17T11:00:48Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:00:48Z DEBUG nsslapd-localuser: 2019-01-17T11:00:48Z DEBUG dirsrv 2019-01-17T11:00:48Z DEBUG nsslapd-security: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordChange: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-port 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:00:48Z DEBUG passwordMaxFailure: 2019-01-17T11:00:48Z DEBUG 3 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:00:48Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:00:48Z DEBUG 128 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:00:48Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-rootdn: 2019-01-17T11:00:48Z DEBUG cn=Directory Manager 2019-01-17T11:00:48Z DEBUG nsslapd-ldifdir: 2019-01-17T11:00:48Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:00:48Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG passwordMustChange: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordExp: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-logging-backend: 2019-01-17T11:00:48Z DEBUG dirsrv-log 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:48Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG aci: 2019-01-17T11:00:48Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:00:48Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:00:48Z DEBUG cn=Directory Manager 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordMinLength: 2019-01-17T11:00:48Z DEBUG 8 2019-01-17T11:00:48Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-idletimeout: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:00:48Z DEBUG -10 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG week 2019-01-17T11:00:48Z DEBUG nsslapd-securePort: 2019-01-17T11:00:48Z DEBUG 636 2019-01-17T11:00:48Z DEBUG nsslapd-snmp-index: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG config 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG extensibleObject 2019-01-17T11:00:48Z DEBUG nsslapdConfig 2019-01-17T11:00:48Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordSendExpiringTime: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-hash-filters: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:00:48Z DEBUG next 2019-01-17T11:00:48Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:00:48Z DEBUG -10 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-listenhost: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordCheckSyntax: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordGraceLimit: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG passwordWarning: 2019-01-17T11:00:48Z DEBUG 86400 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-instancedir: 2019-01-17T11:00:48Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-config: 2019-01-17T11:00:48Z DEBUG cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-versionstring: 2019-01-17T11:00:48Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:00:48Z DEBUG 256 2019-01-17T11:00:48Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:00:48Z DEBUG 2097152 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:00:48Z DEBUG SSHA512 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG passwordLockout: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-lockdir: 2019-01-17T11:00:48Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-certdir: 2019-01-17T11:00:48Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 10 2019-01-17T11:00:48Z DEBUG nsslapd-backendconfig: 2019-01-17T11:00:48Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-threadnumber: 2019-01-17T11:00:48Z DEBUG 24 2019-01-17T11:00:48Z DEBUG nsslapd-schemamod: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-localhost: 2019-01-17T11:00:48Z DEBUG centos75.local 2019-01-17T11:00:48Z DEBUG nsslapd-bakdir: 2019-01-17T11:00:48Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:00:48Z DEBUG passwordMin8bit: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:00:48Z DEBUG uidNumber 2019-01-17T11:00:48Z DEBUG nsslapd-validate-cert: 2019-01-17T11:00:48Z DEBUG warn 2019-01-17T11:00:48Z DEBUG passwordMinCategories: 2019-01-17T11:00:48Z DEBUG 3 2019-01-17T11:00:48Z DEBUG passwordMinLowers: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordAdminDN: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordMinSpecials: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-lastmod: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:00:48Z DEBUG 40 2019-01-17T11:00:48Z DEBUG passwordMaxRepeats: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:00:48Z DEBUG -1 2019-01-17T11:00:48Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:00:48Z DEBUG none 2019-01-17T11:00:48Z DEBUG nsslapd-result-tweak: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG passwordUnlock: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-schemacheck: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-maxbersize: 2019-01-17T11:00:48Z DEBUG 209715200 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:00:48Z DEBUG dc=example,dc=com 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-localssf: 2019-01-17T11:00:48Z DEBUG 71 2019-01-17T11:00:48Z DEBUG nsslapd-sizelimit: 2019-01-17T11:00:48Z DEBUG 2000 2019-01-17T11:00:48Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:00:48Z DEBUG dc=local 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:00:48Z DEBUG 2097152 2019-01-17T11:00:48Z DEBUG passwordLockoutDuration: 2019-01-17T11:00:48Z DEBUG 3600 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-port: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:00:48Z DEBUG cn=schema 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG cn=monitor 2019-01-17T11:00:48Z DEBUG cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-rootpw: 2019-01-17T11:00:48Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:00:48Z DEBUG 300000 2019-01-17T11:00:48Z DEBUG nsslapd-workingdir: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-rundir: 2019-01-17T11:00:48Z DEBUG /var/run/dirsrv 2019-01-17T11:00:48Z DEBUG nsslapd-schemareplace: 2019-01-17T11:00:48Z DEBUG replication-only 2019-01-17T11:00:48Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:00:48Z DEBUG 16384 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:00:48Z DEBUG 10000 2019-01-17T11:00:48Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordMinDigits: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG passwordStorageScheme: 2019-01-17T11:00:48Z DEBUG SSHA512 2019-01-17T11:00:48Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG add: '(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";)' to aci, current value [u'(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";)', u'(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:00:48Z DEBUG add: updated value [u'(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";)', u'(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-betype: 2019-01-17T11:00:48Z DEBUG ldbm database 2019-01-17T11:00:48Z DEBUG nsslapd-nagle: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-referralmode: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:00:48Z DEBUG 64 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 500 2019-01-17T11:00:48Z DEBUG passwordMinAlphas: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-readonly: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordLegacyPolicy: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:00:48Z DEBUG allowed 2019-01-17T11:00:48Z DEBUG passwordMinUppers: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-plugin: 2019-01-17T11:00:48Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:00:48Z DEBUG 2097152 2019-01-17T11:00:48Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:00:48Z DEBUG 20971520 2019-01-17T11:00:48Z DEBUG nsslapd-timelimit: 2019-01-17T11:00:48Z DEBUG 3600 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordMinTokenLength: 2019-01-17T11:00:48Z DEBUG 3 2019-01-17T11:00:48Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:00:48Z DEBUG -10 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG week 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG passwordMinAge: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG week 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:00:48Z DEBUG 60 2019-01-17T11:00:48Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:00:48Z DEBUG 1024 2019-01-17T11:00:48Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordInHistory: 2019-01-17T11:00:48Z DEBUG 6 2019-01-17T11:00:48Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-conntablesize: 2019-01-17T11:00:48Z DEBUG 16384 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG nsslapd-saslpath: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG passwordMaxAge: 2019-01-17T11:00:48Z DEBUG 8640000 2019-01-17T11:00:48Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:00:48Z DEBUG gidNumber 2019-01-17T11:00:48Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG day 2019-01-17T11:00:48Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-csnlogging: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-tmpdir: 2019-01-17T11:00:48Z DEBUG /tmp 2019-01-17T11:00:48Z DEBUG passwordResetFailureCount: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-counters: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-svrtab: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG nsslapd-minssf: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-schemadir: 2019-01-17T11:00:48Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:00:48Z DEBUG nsslapd-localuser: 2019-01-17T11:00:48Z DEBUG dirsrv 2019-01-17T11:00:48Z DEBUG nsslapd-security: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordChange: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-port 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:00:48Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:00:48Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:00:48Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:00:48Z DEBUG passwordMaxFailure: 2019-01-17T11:00:48Z DEBUG 3 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:00:48Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:00:48Z DEBUG 128 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:00:48Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-rootdn: 2019-01-17T11:00:48Z DEBUG cn=Directory Manager 2019-01-17T11:00:48Z DEBUG nsslapd-ldifdir: 2019-01-17T11:00:48Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:00:48Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG passwordMustChange: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordExp: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-logging-backend: 2019-01-17T11:00:48Z DEBUG dirsrv-log 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:48Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG aci: 2019-01-17T11:00:48Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:00:48Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:00:48Z DEBUG cn=Directory Manager 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordMinLength: 2019-01-17T11:00:48Z DEBUG 8 2019-01-17T11:00:48Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-idletimeout: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:00:48Z DEBUG -10 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:00:48Z DEBUG week 2019-01-17T11:00:48Z DEBUG nsslapd-securePort: 2019-01-17T11:00:48Z DEBUG 636 2019-01-17T11:00:48Z DEBUG nsslapd-snmp-index: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG config 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG extensibleObject 2019-01-17T11:00:48Z DEBUG nsslapdConfig 2019-01-17T11:00:48Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordSendExpiringTime: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-hash-filters: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:00:48Z DEBUG next 2019-01-17T11:00:48Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:00:48Z DEBUG -10 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-listenhost: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordCheckSyntax: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordGraceLimit: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG passwordWarning: 2019-01-17T11:00:48Z DEBUG 86400 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-instancedir: 2019-01-17T11:00:48Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-config: 2019-01-17T11:00:48Z DEBUG cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-versionstring: 2019-01-17T11:00:48Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:00:48Z DEBUG 256 2019-01-17T11:00:48Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:00:48Z DEBUG 2097152 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:00:48Z DEBUG SSHA512 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG passwordLockout: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-lockdir: 2019-01-17T11:00:48Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-certdir: 2019-01-17T11:00:48Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 10 2019-01-17T11:00:48Z DEBUG nsslapd-backendconfig: 2019-01-17T11:00:48Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-threadnumber: 2019-01-17T11:00:48Z DEBUG 24 2019-01-17T11:00:48Z DEBUG nsslapd-schemamod: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-localhost: 2019-01-17T11:00:48Z DEBUG centos75.local 2019-01-17T11:00:48Z DEBUG nsslapd-bakdir: 2019-01-17T11:00:48Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:00:48Z DEBUG passwordMin8bit: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:00:48Z DEBUG uidNumber 2019-01-17T11:00:48Z DEBUG nsslapd-validate-cert: 2019-01-17T11:00:48Z DEBUG warn 2019-01-17T11:00:48Z DEBUG passwordMinCategories: 2019-01-17T11:00:48Z DEBUG 3 2019-01-17T11:00:48Z DEBUG passwordMinLowers: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordAdminDN: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordMinSpecials: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-lastmod: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:00:48Z DEBUG 40 2019-01-17T11:00:48Z DEBUG passwordMaxRepeats: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:00:48Z DEBUG -1 2019-01-17T11:00:48Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:00:48Z DEBUG none 2019-01-17T11:00:48Z DEBUG nsslapd-result-tweak: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:00:48Z DEBUG month 2019-01-17T11:00:48Z DEBUG passwordUnlock: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-schemacheck: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-maxbersize: 2019-01-17T11:00:48Z DEBUG 209715200 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:00:48Z DEBUG dc=example,dc=com 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-localssf: 2019-01-17T11:00:48Z DEBUG 71 2019-01-17T11:00:48Z DEBUG nsslapd-sizelimit: 2019-01-17T11:00:48Z DEBUG 2000 2019-01-17T11:00:48Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:00:48Z DEBUG dc=local 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:00:48Z DEBUG 2097152 2019-01-17T11:00:48Z DEBUG passwordLockoutDuration: 2019-01-17T11:00:48Z DEBUG 3600 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-port: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:00:48Z DEBUG cn=schema 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG cn=monitor 2019-01-17T11:00:48Z DEBUG cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:00:48Z DEBUG 1 2019-01-17T11:00:48Z DEBUG nsslapd-auditlog: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:00:48Z DEBUG 600 2019-01-17T11:00:48Z DEBUG nsslapd-rootpw: 2019-01-17T11:00:48Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:00:48Z DEBUG 300000 2019-01-17T11:00:48Z DEBUG nsslapd-workingdir: 2019-01-17T11:00:48Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:00:48Z DEBUG 2019-01-17T11:00:48Z DEBUG nsslapd-rundir: 2019-01-17T11:00:48Z DEBUG /var/run/dirsrv 2019-01-17T11:00:48Z DEBUG nsslapd-schemareplace: 2019-01-17T11:00:48Z DEBUG replication-only 2019-01-17T11:00:48Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:00:48Z DEBUG 16384 2019-01-17T11:00:48Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:00:48Z DEBUG 10000 2019-01-17T11:00:48Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG passwordMinDigits: 2019-01-17T11:00:48Z DEBUG 0 2019-01-17T11:00:48Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:00:48Z DEBUG 5 2019-01-17T11:00:48Z DEBUG passwordStorageScheme: 2019-01-17T11:00:48Z DEBUG SSHA512 2019-01-17T11:00:48Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG [] 2019-01-17T11:00:48Z DEBUG Updated 0 2019-01-17T11:00:48Z DEBUG Done 2019-01-17T11:00:48Z DEBUG New entry: cn=CA Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=CA Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG CA Administrator 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG CA Administrator 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=CA Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG CA Administrator 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG CA Administrator 2019-01-17T11:00:48Z ERROR Parent DN of cn=CA Administrator,cn=privileges,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=Vault Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=Vault Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Vault Administrators 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG Vault Administrators 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=Vault Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Vault Administrators 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG Vault Administrators 2019-01-17T11:00:48Z ERROR Parent DN of cn=Vault Administrators,cn=privileges,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=DNS Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=DNS Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG DNS Administrators 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG DNS Administrators 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=DNS Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG DNS Administrators 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG DNS Administrators 2019-01-17T11:00:48Z ERROR Parent DN of cn=DNS Administrators,cn=privileges,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=DNS Servers,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=DNS Servers,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG DNS Servers 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG DNS Servers 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=DNS Servers,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG DNS Servers 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG DNS Servers 2019-01-17T11:00:48Z ERROR Parent DN of cn=DNS Servers,cn=privileges,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG Parsing update file '/usr/share/ipa/updates/40-dns.update' 2019-01-17T11:00:48Z DEBUG New entry: cn=dns,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=dns,dc=local 2019-01-17T11:00:48Z DEBUG addifexist: 'idnsConfigObject' to objectClass, current value [] 2019-01-17T11:00:48Z DEBUG addifexist: '(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)' to aci, current value [] 2019-01-17T11:00:48Z DEBUG addifexist: '(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";)' to aci, current value [] 2019-01-17T11:00:48Z DEBUG addifexist: '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' to aci, current value [] 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=dns,dc=local 2019-01-17T11:00:48Z DEBUG New entry: cn=dns,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=dns,dc=local 2019-01-17T11:00:48Z DEBUG replace: (targetattr = "*")(version 3.0; acl "No access to DNS tree without a permission"; deny (read,search,compare) (groupdn != "ldap:///cn=admins,cn=groups,cn=accounts,dc=local") and (groupdn != "ldap:///cn=Read DNS Entries,cn=permissions,cn=pbac,dc=local");) not found, skipping 2019-01-17T11:00:48Z DEBUG replace: (targetattr = "*")(version 3.0; acl "Allow read access"; allow (read,search,compare) groupdn = "ldap:///cn=Read DNS Entries,cn=permissions,cn=pbac,dc=local" or userattr = "parent[0,1].managedby#GROUPDN";) not found, skipping 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=dns,dc=local 2019-01-17T11:00:48Z DEBUG New entry: cn=dns,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=dns,dc=local 2019-01-17T11:00:48Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders")(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' from aci, current value [] 2019-01-17T11:00:48Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders")(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' not in aci 2019-01-17T11:00:48Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders || dlvrecord || idnssecinlinesigning || nsec3paramrecord || tlsarecord ")(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' from aci, current value [] 2019-01-17T11:00:48Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders || dlvrecord || idnssecinlinesigning || nsec3paramrecord || tlsarecord ")(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' not in aci 2019-01-17T11:00:48Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders || dlvrecord || idnssecinlinesigning || nsec3paramrecord || tlsarecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' from aci, current value [] 2019-01-17T11:00:48Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders || dlvrecord || idnssecinlinesigning || nsec3paramrecord || tlsarecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' not in aci 2019-01-17T11:00:48Z DEBUG remove: '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' from aci, current value [] 2019-01-17T11:00:48Z DEBUG remove: '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' not in aci 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=dns,dc=local 2019-01-17T11:00:48Z DEBUG Updating existing entry: cn=IPA DNS,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=IPA DNS,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:48Z DEBUG ipa_dns 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG IPA DNS 2019-01-17T11:00:48Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:48Z DEBUG 1.0 2019-01-17T11:00:48Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:48Z DEBUG IPA DNS support plugin 2019-01-17T11:00:48Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:48Z DEBUG libipa_dns.so 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG nsslapdPlugin 2019-01-17T11:00:48Z DEBUG extensibleObject 2019-01-17T11:00:48Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:48Z DEBUG database 2019-01-17T11:00:48Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:48Z DEBUG Red Hat, Inc. 2019-01-17T11:00:48Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:48Z DEBUG preoperation 2019-01-17T11:00:48Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:48Z DEBUG ipadns_init 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=IPA DNS,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:48Z DEBUG ipa_dns 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG IPA DNS 2019-01-17T11:00:48Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:48Z DEBUG 1.0 2019-01-17T11:00:48Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:48Z DEBUG IPA DNS support plugin 2019-01-17T11:00:48Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:48Z DEBUG libipa_dns.so 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG nsslapdPlugin 2019-01-17T11:00:48Z DEBUG extensibleObject 2019-01-17T11:00:48Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:48Z DEBUG database 2019-01-17T11:00:48Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:48Z DEBUG Red Hat, Inc. 2019-01-17T11:00:48Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:48Z DEBUG preoperation 2019-01-17T11:00:48Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:48Z DEBUG ipadns_init 2019-01-17T11:00:48Z DEBUG [] 2019-01-17T11:00:48Z DEBUG Updated 0 2019-01-17T11:00:48Z DEBUG Done 2019-01-17T11:00:48Z DEBUG Parsing update file '/usr/share/ipa/updates/40-otp.update' 2019-01-17T11:00:48Z DEBUG New entry: cn=otp,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=otp,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG nsContainer 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG otp 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=otp,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG nsContainer 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG otp 2019-01-17T11:00:48Z ERROR Parent DN of cn=otp,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=otp,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=otp,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG ipatokenHOTPsyncWindow: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG ipatokenHOTPauthWindow: 2019-01-17T11:00:48Z DEBUG 10 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG otp 2019-01-17T11:00:48Z DEBUG ipatokenTOTPsyncWindow: 2019-01-17T11:00:48Z DEBUG 86400 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG ipatokenOTPConfig 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG ipatokenTOTPauthWindow: 2019-01-17T11:00:48Z DEBUG 300 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=otp,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG ipatokenHOTPsyncWindow: 2019-01-17T11:00:48Z DEBUG 100 2019-01-17T11:00:48Z DEBUG ipatokenHOTPauthWindow: 2019-01-17T11:00:48Z DEBUG 10 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG otp 2019-01-17T11:00:48Z DEBUG ipatokenTOTPsyncWindow: 2019-01-17T11:00:48Z DEBUG 86400 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG ipatokenOTPConfig 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG ipatokenTOTPauthWindow: 2019-01-17T11:00:48Z DEBUG 300 2019-01-17T11:00:48Z ERROR Parent DN of cn=otp,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: dc=local 2019-01-17T11:00:48Z DEBUG remove: '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create and delete tokens"; allow (add, delete) userattr = "ipatokenOwner#SELFDN";)' from aci, current value [] 2019-01-17T11:00:48Z DEBUG remove: '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create and delete tokens"; allow (add, delete) userattr = "ipatokenOwner#SELFDN";)' not in aci 2019-01-17T11:00:48Z DEBUG remove: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || ipatokenUniqueID || description || ipatokenOwner || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Users can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN";)' from aci, current value [] 2019-01-17T11:00:48Z DEBUG remove: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || ipatokenUniqueID || description || ipatokenOwner || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Users can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN";)' not in aci 2019-01-17T11:00:48Z DEBUG remove: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "ipatokenUniqueID || description || ipatokenOwner || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Users can write basic token info"; allow (write) userattr = "ipatokenOwner#USERDN";)' from aci, current value [] 2019-01-17T11:00:48Z DEBUG remove: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "ipatokenUniqueID || description || ipatokenOwner || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Users can write basic token info"; allow (write) userattr = "ipatokenOwner#USERDN";)' not in aci 2019-01-17T11:00:48Z DEBUG remove: '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPkey || ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPclockOffset || ipatokenTOTPtimeStep")(version 3.0; acl "Users can add TOTP token secrets"; allow (write, search) userattr = "ipatokenOwner#USERDN";)' from aci, current value [] 2019-01-17T11:00:48Z DEBUG remove: '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPkey || ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPclockOffset || ipatokenTOTPtimeStep")(version 3.0; acl "Users can add TOTP token secrets"; allow (write, search) userattr = "ipatokenOwner#USERDN";)' not in aci 2019-01-17T11:00:48Z DEBUG remove: '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPkey || ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenHOTPcounter")(version 3.0; acl "Users can add HOTP token secrets"; allow (write, search) userattr = "ipatokenOwner#USERDN";)' from aci, current value [] 2019-01-17T11:00:48Z DEBUG remove: '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPkey || ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenHOTPcounter")(version 3.0; acl "Users can add HOTP token secrets"; allow (write, search) userattr = "ipatokenOwner#USERDN";)' not in aci 2019-01-17T11:00:48Z DEBUG add: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)' to aci, current value [] 2019-01-17T11:00:48Z DEBUG add: updated value [u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2019-01-17T11:00:48Z DEBUG add: '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)' to aci, current value [u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2019-01-17T11:00:48Z DEBUG add: updated value [u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2019-01-17T11:00:48Z DEBUG add: '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)' to aci, current value [u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2019-01-17T11:00:48Z DEBUG add: updated value [u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2019-01-17T11:00:48Z DEBUG add: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)' to aci, current value [u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2019-01-17T11:00:48Z DEBUG add: updated value [u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)'] 2019-01-17T11:00:48Z DEBUG add: '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)' to aci, current value [u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)'] 2019-01-17T11:00:48Z DEBUG add: updated value [u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)'] 2019-01-17T11:00:48Z DEBUG add: '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)' to aci, current value [u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)'] 2019-01-17T11:00:48Z DEBUG add: updated value [u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)'] 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: dc=local 2019-01-17T11:00:48Z DEBUG aci: 2019-01-17T11:00:48Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:00:48Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:00:48Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:00:48Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2019-01-17T11:00:48Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2019-01-17T11:00:48Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2019-01-17T11:00:48Z ERROR Add failure missing required attribute "objectclass" 2019-01-17T11:00:48Z DEBUG New entry: cn=radiusproxy,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=radiusproxy,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG nsContainer 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG radiusproxy 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=radiusproxy,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG nsContainer 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG radiusproxy 2019-01-17T11:00:48Z ERROR Parent DN of cn=radiusproxy,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG Updating existing entry: cn=IPA OTP Last Token,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=IPA OTP Last Token,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:48Z DEBUG ipa-otp-lasttoken 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG IPA OTP Last Token 2019-01-17T11:00:48Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:48Z DEBUG FreeIPA/1.0 2019-01-17T11:00:48Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:48Z DEBUG Protect the user's last active token 2019-01-17T11:00:48Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:48Z DEBUG libipa_otp_lasttoken 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG nsSlapdPlugin 2019-01-17T11:00:48Z DEBUG extensibleObject 2019-01-17T11:00:48Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:48Z DEBUG database 2019-01-17T11:00:48Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:48Z DEBUG FreeIPA 2019-01-17T11:00:48Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:48Z DEBUG preoperation 2019-01-17T11:00:48Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:48Z DEBUG ipa_otp_lasttoken_init 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=IPA OTP Last Token,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:48Z DEBUG ipa-otp-lasttoken 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG IPA OTP Last Token 2019-01-17T11:00:48Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:48Z DEBUG FreeIPA/1.0 2019-01-17T11:00:48Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:48Z DEBUG Protect the user's last active token 2019-01-17T11:00:48Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:48Z DEBUG libipa_otp_lasttoken 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG nsSlapdPlugin 2019-01-17T11:00:48Z DEBUG extensibleObject 2019-01-17T11:00:48Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:48Z DEBUG database 2019-01-17T11:00:48Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:48Z DEBUG FreeIPA 2019-01-17T11:00:48Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:48Z DEBUG preoperation 2019-01-17T11:00:48Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:48Z DEBUG ipa_otp_lasttoken_init 2019-01-17T11:00:48Z DEBUG [] 2019-01-17T11:00:48Z DEBUG Updated 0 2019-01-17T11:00:48Z DEBUG Done 2019-01-17T11:00:48Z DEBUG Updating existing entry: cn=IPA OTP Counter,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=IPA OTP Counter,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:48Z DEBUG ipa-otp-counter 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG IPA OTP Counter 2019-01-17T11:00:48Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:48Z DEBUG FreeIPA/1.0 2019-01-17T11:00:48Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:48Z DEBUG Ensure proper OTP token counter operation 2019-01-17T11:00:48Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:48Z DEBUG libipa_otp_counter 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG nsSlapdPlugin 2019-01-17T11:00:48Z DEBUG extensibleObject 2019-01-17T11:00:48Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:48Z DEBUG database 2019-01-17T11:00:48Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:48Z DEBUG FreeIPA 2019-01-17T11:00:48Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:48Z DEBUG preoperation 2019-01-17T11:00:48Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:48Z DEBUG ipa_otp_counter_init 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=IPA OTP Counter,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:48Z DEBUG ipa-otp-counter 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG IPA OTP Counter 2019-01-17T11:00:48Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:48Z DEBUG FreeIPA/1.0 2019-01-17T11:00:48Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:48Z DEBUG Ensure proper OTP token counter operation 2019-01-17T11:00:48Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:48Z DEBUG libipa_otp_counter 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG nsSlapdPlugin 2019-01-17T11:00:48Z DEBUG extensibleObject 2019-01-17T11:00:48Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:48Z DEBUG database 2019-01-17T11:00:48Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:48Z DEBUG FreeIPA 2019-01-17T11:00:48Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:48Z DEBUG preoperation 2019-01-17T11:00:48Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:48Z DEBUG ipa_otp_counter_init 2019-01-17T11:00:48Z DEBUG [] 2019-01-17T11:00:48Z DEBUG Updated 0 2019-01-17T11:00:48Z DEBUG Done 2019-01-17T11:00:48Z DEBUG Parsing update file '/usr/share/ipa/updates/40-realm_domains.update' 2019-01-17T11:00:48Z DEBUG New entry: cn=Realm Domains,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=Realm Domains,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG domainRelatedObject 2019-01-17T11:00:48Z DEBUG nsContainer 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG associatedDomain: 2019-01-17T11:00:48Z DEBUG local 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Realm Domains 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=Realm Domains,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG domainRelatedObject 2019-01-17T11:00:48Z DEBUG nsContainer 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG associatedDomain: 2019-01-17T11:00:48Z DEBUG local 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Realm Domains 2019-01-17T11:00:48Z ERROR Parent DN of cn=Realm Domains,cn=ipa,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG Parsing update file '/usr/share/ipa/updates/40-replication.update' 2019-01-17T11:00:48Z DEBUG Updating existing entry: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-directory: 2019-01-17T11:00:48Z DEBUG /var/lib/dirsrv/slapd-LOCAL/db/userRoot 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG userRoot 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG extensibleObject 2019-01-17T11:00:48Z DEBUG nsBackendInstance 2019-01-17T11:00:48Z DEBUG nsslapd-require-index: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG aci: 2019-01-17T11:00:48Z DEBUG (targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG nsslapd-suffix: 2019-01-17T11:00:48Z DEBUG dc=local 2019-01-17T11:00:48Z DEBUG nsslapd-readonly: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-dncachememsize: 2019-01-17T11:00:48Z DEBUG 67108864 2019-01-17T11:00:48Z DEBUG nsslapd-cachesize: 2019-01-17T11:00:48Z DEBUG -1 2019-01-17T11:00:48Z DEBUG nsslapd-cachememsize: 2019-01-17T11:00:48Z DEBUG 67108864 2019-01-17T11:00:48Z DEBUG add: '(targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";)' to aci, current value [u'(targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:00:48Z DEBUG add: updated value [u'(targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-directory: 2019-01-17T11:00:48Z DEBUG /var/lib/dirsrv/slapd-LOCAL/db/userRoot 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG userRoot 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG extensibleObject 2019-01-17T11:00:48Z DEBUG nsBackendInstance 2019-01-17T11:00:48Z DEBUG nsslapd-require-index: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG aci: 2019-01-17T11:00:48Z DEBUG (targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG nsslapd-suffix: 2019-01-17T11:00:48Z DEBUG dc=local 2019-01-17T11:00:48Z DEBUG nsslapd-readonly: 2019-01-17T11:00:48Z DEBUG off 2019-01-17T11:00:48Z DEBUG nsslapd-dncachememsize: 2019-01-17T11:00:48Z DEBUG 67108864 2019-01-17T11:00:48Z DEBUG nsslapd-cachesize: 2019-01-17T11:00:48Z DEBUG -1 2019-01-17T11:00:48Z DEBUG nsslapd-cachememsize: 2019-01-17T11:00:48Z DEBUG 67108864 2019-01-17T11:00:48Z DEBUG [] 2019-01-17T11:00:48Z DEBUG Updated 0 2019-01-17T11:00:48Z DEBUG Done 2019-01-17T11:00:48Z DEBUG New entry: cn=Modify DNA Range,cn=permissions,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=Modify DNA Range,cn=permissions,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG ipapermission 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG ipapermissiontype: 2019-01-17T11:00:48Z DEBUG SYSTEM 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Modify DNA Range 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=Modify DNA Range,cn=permissions,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG ipapermission 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG ipapermissiontype: 2019-01-17T11:00:48Z DEBUG SYSTEM 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Modify DNA Range 2019-01-17T11:00:48Z ERROR Parent DN of cn=Modify DNA Range,cn=permissions,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG Updating existing entry: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG dnaScope: 2019-01-17T11:00:48Z DEBUG dc=local 2019-01-17T11:00:48Z DEBUG dnaThreshold: 2019-01-17T11:00:48Z DEBUG 500 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Posix IDs 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG extensibleObject 2019-01-17T11:00:48Z DEBUG aci: 2019-01-17T11:00:48Z DEBUG (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG dnaMagicRegen: 2019-01-17T11:00:48Z DEBUG -1 2019-01-17T11:00:48Z DEBUG dnaNextValue: 2019-01-17T11:00:48Z DEBUG 353600000 2019-01-17T11:00:48Z DEBUG dnaExcludeScope: 2019-01-17T11:00:48Z DEBUG cn=provisioning,dc=local 2019-01-17T11:00:48Z DEBUG dnaFilter: 2019-01-17T11:00:48Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2019-01-17T11:00:48Z DEBUG dnaType: 2019-01-17T11:00:48Z DEBUG uidNumber 2019-01-17T11:00:48Z DEBUG gidNumber 2019-01-17T11:00:48Z DEBUG dnaMaxValue: 2019-01-17T11:00:48Z DEBUG 353799999 2019-01-17T11:00:48Z DEBUG dnaSharedCfgDN: 2019-01-17T11:00:48Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG add: '(targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=local";)' to aci, current value [u'(targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:00:48Z DEBUG add: updated value [u'(targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG dnaScope: 2019-01-17T11:00:48Z DEBUG dc=local 2019-01-17T11:00:48Z DEBUG dnaThreshold: 2019-01-17T11:00:48Z DEBUG 500 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Posix IDs 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG extensibleObject 2019-01-17T11:00:48Z DEBUG aci: 2019-01-17T11:00:48Z DEBUG (targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG dnaMagicRegen: 2019-01-17T11:00:48Z DEBUG -1 2019-01-17T11:00:48Z DEBUG dnaNextValue: 2019-01-17T11:00:48Z DEBUG 353600000 2019-01-17T11:00:48Z DEBUG dnaExcludeScope: 2019-01-17T11:00:48Z DEBUG cn=provisioning,dc=local 2019-01-17T11:00:48Z DEBUG dnaFilter: 2019-01-17T11:00:48Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2019-01-17T11:00:48Z DEBUG dnaType: 2019-01-17T11:00:48Z DEBUG uidNumber 2019-01-17T11:00:48Z DEBUG gidNumber 2019-01-17T11:00:48Z DEBUG dnaMaxValue: 2019-01-17T11:00:48Z DEBUG 353799999 2019-01-17T11:00:48Z DEBUG dnaSharedCfgDN: 2019-01-17T11:00:48Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG [] 2019-01-17T11:00:48Z DEBUG Updated 0 2019-01-17T11:00:48Z DEBUG Done 2019-01-17T11:00:48Z DEBUG New entry: cn=Read DNA Range,cn=permissions,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=Read DNA Range,cn=permissions,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG ipapermission 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG ipapermissiontype: 2019-01-17T11:00:48Z DEBUG SYSTEM 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Read DNA Range 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=Read DNA Range,cn=permissions,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG ipapermission 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG ipapermissiontype: 2019-01-17T11:00:48Z DEBUG SYSTEM 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Read DNA Range 2019-01-17T11:00:48Z ERROR Parent DN of cn=Read DNA Range,cn=permissions,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG Updating existing entry: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG dnaScope: 2019-01-17T11:00:48Z DEBUG dc=local 2019-01-17T11:00:48Z DEBUG dnaThreshold: 2019-01-17T11:00:48Z DEBUG 500 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Posix IDs 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG extensibleObject 2019-01-17T11:00:48Z DEBUG aci: 2019-01-17T11:00:48Z DEBUG (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG dnaMagicRegen: 2019-01-17T11:00:48Z DEBUG -1 2019-01-17T11:00:48Z DEBUG dnaNextValue: 2019-01-17T11:00:48Z DEBUG 353600000 2019-01-17T11:00:48Z DEBUG dnaExcludeScope: 2019-01-17T11:00:48Z DEBUG cn=provisioning,dc=local 2019-01-17T11:00:48Z DEBUG dnaFilter: 2019-01-17T11:00:48Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2019-01-17T11:00:48Z DEBUG dnaType: 2019-01-17T11:00:48Z DEBUG uidNumber 2019-01-17T11:00:48Z DEBUG gidNumber 2019-01-17T11:00:48Z DEBUG dnaMaxValue: 2019-01-17T11:00:48Z DEBUG 353799999 2019-01-17T11:00:48Z DEBUG dnaSharedCfgDN: 2019-01-17T11:00:48Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG add: '(targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=local";)' to aci, current value [u'(targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:00:48Z DEBUG add: updated value [u'(targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG dnaScope: 2019-01-17T11:00:48Z DEBUG dc=local 2019-01-17T11:00:48Z DEBUG dnaThreshold: 2019-01-17T11:00:48Z DEBUG 500 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Posix IDs 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG extensibleObject 2019-01-17T11:00:48Z DEBUG aci: 2019-01-17T11:00:48Z DEBUG (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG (targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:48Z DEBUG dnaMagicRegen: 2019-01-17T11:00:48Z DEBUG -1 2019-01-17T11:00:48Z DEBUG dnaNextValue: 2019-01-17T11:00:48Z DEBUG 353600000 2019-01-17T11:00:48Z DEBUG dnaExcludeScope: 2019-01-17T11:00:48Z DEBUG cn=provisioning,dc=local 2019-01-17T11:00:48Z DEBUG dnaFilter: 2019-01-17T11:00:48Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2019-01-17T11:00:48Z DEBUG dnaType: 2019-01-17T11:00:48Z DEBUG uidNumber 2019-01-17T11:00:48Z DEBUG gidNumber 2019-01-17T11:00:48Z DEBUG dnaMaxValue: 2019-01-17T11:00:48Z DEBUG 353799999 2019-01-17T11:00:48Z DEBUG dnaSharedCfgDN: 2019-01-17T11:00:48Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG [] 2019-01-17T11:00:48Z DEBUG Updated 0 2019-01-17T11:00:48Z DEBUG Done 2019-01-17T11:00:48Z DEBUG Parsing update file '/usr/share/ipa/updates/40-vault.update' 2019-01-17T11:00:48Z DEBUG New entry: cn=vaults,cn=kra,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=vaults,cn=kra,dc=local 2019-01-17T11:00:48Z DEBUG remove: '(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=local")(version 3.0; acl "Allow users to create private container"; allow (add) userdn = "ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=local";)' from aci, current value [] 2019-01-17T11:00:48Z DEBUG remove: '(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=local")(version 3.0; acl "Allow users to create private container"; allow (add) userdn = "ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=local";)' not in aci 2019-01-17T11:00:48Z DEBUG remove: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=local")(version 3.0; acl "Allow services to create private container"; allow (add) userdn = "ldap:///krbprincipalname=($attr.cn)@LOCAL,cn=services,cn=accounts,dc=local";)' from aci, current value [] 2019-01-17T11:00:48Z DEBUG remove: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=local")(version 3.0; acl "Allow services to create private container"; allow (add) userdn = "ldap:///krbprincipalname=($attr.cn)@LOCAL,cn=services,cn=accounts,dc=local";)' not in aci 2019-01-17T11:00:48Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Container owners can manage vaults in the container"; allow(read, search, compare, add, delete) userattr="parent[1].owner#USERDN";)' from aci, current value [] 2019-01-17T11:00:48Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Container owners can manage vaults in the container"; allow(read, search, compare, add, delete) userattr="parent[1].owner#USERDN";)' not in aci 2019-01-17T11:00:48Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect container owners can manage vaults in the container"; allow(read, search, compare, add, delete) userattr="parent[1].owner#GROUPDN";)' from aci, current value [] 2019-01-17T11:00:48Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect container owners can manage vaults in the container"; allow(read, search, compare, add, delete) userattr="parent[1].owner#GROUPDN";)' not in aci 2019-01-17T11:00:48Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Vault members can access the vault"; allow(read, search, compare) userattr="member#USERDN";)' from aci, current value [] 2019-01-17T11:00:48Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Vault members can access the vault"; allow(read, search, compare) userattr="member#USERDN";)' not in aci 2019-01-17T11:00:48Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect vault members can access the vault"; allow(read, search, compare) userattr="member#GROUPDN";)' from aci, current value [] 2019-01-17T11:00:48Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect vault members can access the vault"; allow(read, search, compare) userattr="member#GROUPDN";)' not in aci 2019-01-17T11:00:48Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Vault owners can manage the vault"; allow(read, search, compare, write) userattr="owner#USERDN";)' from aci, current value [] 2019-01-17T11:00:48Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Vault owners can manage the vault"; allow(read, search, compare, write) userattr="owner#USERDN";)' not in aci 2019-01-17T11:00:48Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect vault owners can manage the vault"; allow(read, search, compare, write) userattr="owner#GROUPDN";)' from aci, current value [] 2019-01-17T11:00:48Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect vault owners can manage the vault"; allow(read, search, compare, write) userattr="owner#GROUPDN";)' not in aci 2019-01-17T11:00:48Z DEBUG remove: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=local")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn)@LOCAL,cn=services,cn=accounts,dc=local" and userattr="owner#SELFDN";)' from aci, current value [] 2019-01-17T11:00:48Z DEBUG remove: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=local")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn)@LOCAL,cn=services,cn=accounts,dc=local" and userattr="owner#SELFDN";)' not in aci 2019-01-17T11:00:48Z DEBUG addifexist: '(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=local")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=local" and userattr="owner#SELFDN";)' to aci, current value [] 2019-01-17T11:00:48Z DEBUG addifexist: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=local")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn),cn=services,cn=accounts,dc=local" and userattr="owner#SELFDN";)' to aci, current value [] 2019-01-17T11:00:48Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Container owners can access the container"; allow(read, search, compare) userattr="owner#USERDN";)' to aci, current value [] 2019-01-17T11:00:48Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Indirect container owners can access the container"; allow(read, search, compare) userattr="owner#GROUPDN";)' to aci, current value [] 2019-01-17T11:00:48Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Container owners can manage the container"; allow(write, delete) userattr="owner#USERDN";)' to aci, current value [] 2019-01-17T11:00:48Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Indirect container owners can manage the container"; allow(write, delete) userattr="owner#GROUPDN";)' to aci, current value [] 2019-01-17T11:00:48Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#USERDN" and userattr="owner#SELFDN";)' to aci, current value [] 2019-01-17T11:00:48Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Indirect container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#GROUPDN" and userattr="owner#SELFDN";)' to aci, current value [] 2019-01-17T11:00:48Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault owners can access the vault"; allow(read, search, compare) userattr="owner#USERDN";)' to aci, current value [] 2019-01-17T11:00:48Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Indirect vault owners can access the vault"; allow(read, search, compare) userattr="owner#GROUPDN";)' to aci, current value [] 2019-01-17T11:00:48Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault members can access the vault"; allow(read, search, compare) userattr="member#USERDN";)' to aci, current value [] 2019-01-17T11:00:48Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Indirect vault members can access the vault"; allow(read, search, compare) userattr="member#GROUPDN";)' to aci, current value [] 2019-01-17T11:00:48Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || member")(version 3.0; acl "Vault owners can manage the vault"; allow(write, delete) userattr="owner#USERDN";)' to aci, current value [] 2019-01-17T11:00:48Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || member")(version 3.0; acl "Indirect vault owners can manage the vault"; allow(write, delete) userattr="owner#GROUPDN";)' to aci, current value [] 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=vaults,cn=kra,dc=local 2019-01-17T11:00:48Z DEBUG Parsing update file '/usr/share/ipa/updates/41-caacl.update' 2019-01-17T11:00:48Z DEBUG New entry: cn=caacls,cn=ca,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=caacls,cn=ca,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG nsContainer 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG caacls 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=caacls,cn=ca,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG nsContainer 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG caacls 2019-01-17T11:00:48Z ERROR Parent DN of cn=caacls,cn=ca,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG Parsing update file '/usr/share/ipa/updates/41-lightweight-cas.update' 2019-01-17T11:00:48Z DEBUG New entry: cn=cas,cn=ca,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=cas,cn=ca,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG nsContainer 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG cas 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=cas,cn=ca,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG nsContainer 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG cas 2019-01-17T11:00:48Z ERROR Parent DN of cn=cas,cn=ca,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG Parsing update file '/usr/share/ipa/updates/45-roles.update' 2019-01-17T11:00:48Z DEBUG New entry: cn=Modify Users and Reset passwords,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=Modify Users and Reset passwords,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=helpdesk,cn=roles,cn=accounts,dc=local 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Modify Users and Reset passwords 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG Modify Users and Reset passwords 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=Modify Users and Reset passwords,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=helpdesk,cn=roles,cn=accounts,dc=local 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Modify Users and Reset passwords 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG Modify Users and Reset passwords 2019-01-17T11:00:48Z ERROR Parent DN of cn=Modify Users and Reset passwords,cn=privileges,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=Modify Group membership,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=Modify Group membership,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=helpdesk,cn=roles,cn=accounts,dc=local 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Modify Group membership 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG Modify Group membership 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=Modify Group membership,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=helpdesk,cn=roles,cn=accounts,dc=local 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Modify Group membership 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG Modify Group membership 2019-01-17T11:00:48Z ERROR Parent DN of cn=Modify Group membership,cn=privileges,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=User Administrator,cn=roles,cn=accounts,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=User Administrator,cn=roles,cn=accounts,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG User Administrator 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG Responsible for creating Users and Groups 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=User Administrator,cn=roles,cn=accounts,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG User Administrator 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG Responsible for creating Users and Groups 2019-01-17T11:00:48Z ERROR Parent DN of cn=User Administrator,cn=roles,cn=accounts,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=User Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=User Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG add: 'cn=User Administrator,cn=roles,cn=accounts,dc=local' to member, current value [] 2019-01-17T11:00:48Z DEBUG add: updated value [u'cn=User Administrator,cn=roles,cn=accounts,dc=local'] 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=User Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=User Administrator,cn=roles,cn=accounts,dc=local 2019-01-17T11:00:48Z ERROR Parent DN of cn=User Administrators,cn=privileges,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=Group Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=Group Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG add: 'cn=User Administrator,cn=roles,cn=accounts,dc=local' to member, current value [] 2019-01-17T11:00:48Z DEBUG add: updated value [u'cn=User Administrator,cn=roles,cn=accounts,dc=local'] 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=Group Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=User Administrator,cn=roles,cn=accounts,dc=local 2019-01-17T11:00:48Z ERROR Parent DN of cn=Group Administrators,cn=privileges,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=Stage User Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=Stage User Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Stage User Administrators 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG Stage User Administrators 2019-01-17T11:00:48Z DEBUG add: 'cn=User Administrator,cn=roles,cn=accounts,dc=local' to member, current value [] 2019-01-17T11:00:48Z DEBUG add: updated value [u'cn=User Administrator,cn=roles,cn=accounts,dc=local'] 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=Stage User Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=User Administrator,cn=roles,cn=accounts,dc=local 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Stage User Administrators 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG Stage User Administrators 2019-01-17T11:00:48Z ERROR Parent DN of cn=Stage User Administrators,cn=privileges,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=IT Specialist,cn=roles,cn=accounts,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=IT Specialist,cn=roles,cn=accounts,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG IT Specialist 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG IT Specialist 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=IT Specialist,cn=roles,cn=accounts,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG IT Specialist 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG IT Specialist 2019-01-17T11:00:48Z ERROR Parent DN of cn=IT Specialist,cn=roles,cn=accounts,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=Host Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=Host Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG add: 'cn=IT Specialist,cn=roles,cn=accounts,dc=local' to member, current value [] 2019-01-17T11:00:48Z DEBUG add: updated value [u'cn=IT Specialist,cn=roles,cn=accounts,dc=local'] 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=Host Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=IT Specialist,cn=roles,cn=accounts,dc=local 2019-01-17T11:00:48Z ERROR Parent DN of cn=Host Administrators,cn=privileges,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=Host Group Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=Host Group Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG add: 'cn=IT Specialist,cn=roles,cn=accounts,dc=local' to member, current value [] 2019-01-17T11:00:48Z DEBUG add: updated value [u'cn=IT Specialist,cn=roles,cn=accounts,dc=local'] 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=Host Group Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=IT Specialist,cn=roles,cn=accounts,dc=local 2019-01-17T11:00:48Z ERROR Parent DN of cn=Host Group Administrators,cn=privileges,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=Service Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=Service Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG add: 'cn=IT Specialist,cn=roles,cn=accounts,dc=local' to member, current value [] 2019-01-17T11:00:48Z DEBUG add: updated value [u'cn=IT Specialist,cn=roles,cn=accounts,dc=local'] 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=Service Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=IT Specialist,cn=roles,cn=accounts,dc=local 2019-01-17T11:00:48Z ERROR Parent DN of cn=Service Administrators,cn=privileges,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=Automount Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=Automount Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG add: 'cn=IT Specialist,cn=roles,cn=accounts,dc=local' to member, current value [] 2019-01-17T11:00:48Z DEBUG add: updated value [u'cn=IT Specialist,cn=roles,cn=accounts,dc=local'] 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=Automount Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=IT Specialist,cn=roles,cn=accounts,dc=local 2019-01-17T11:00:48Z ERROR Parent DN of cn=Automount Administrators,cn=privileges,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=IT Security Specialist,cn=roles,cn=accounts,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=IT Security Specialist,cn=roles,cn=accounts,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG IT Security Specialist 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG IT Security Specialist 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=IT Security Specialist,cn=roles,cn=accounts,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG IT Security Specialist 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG IT Security Specialist 2019-01-17T11:00:48Z ERROR Parent DN of cn=IT Security Specialist,cn=roles,cn=accounts,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=Netgroups Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=Netgroups Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG add: 'cn=IT Security Specialist,cn=roles,cn=accounts,dc=local' to member, current value [] 2019-01-17T11:00:48Z DEBUG add: updated value [u'cn=IT Security Specialist,cn=roles,cn=accounts,dc=local'] 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=Netgroups Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=IT Security Specialist,cn=roles,cn=accounts,dc=local 2019-01-17T11:00:48Z ERROR Parent DN of cn=Netgroups Administrators,cn=privileges,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG add: 'cn=IT Security Specialist,cn=roles,cn=accounts,dc=local' to member, current value [] 2019-01-17T11:00:48Z DEBUG add: updated value [u'cn=IT Security Specialist,cn=roles,cn=accounts,dc=local'] 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=IT Security Specialist,cn=roles,cn=accounts,dc=local 2019-01-17T11:00:48Z ERROR Parent DN of cn=HBAC Administrator,cn=privileges,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=Sudo administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=Sudo administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG add: 'cn=IT Security Specialist,cn=roles,cn=accounts,dc=local' to member, current value [] 2019-01-17T11:00:48Z DEBUG add: updated value [u'cn=IT Security Specialist,cn=roles,cn=accounts,dc=local'] 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=Sudo administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=IT Security Specialist,cn=roles,cn=accounts,dc=local 2019-01-17T11:00:48Z ERROR Parent DN of cn=Sudo administrator,cn=privileges,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=Security Architect,cn=roles,cn=accounts,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=Security Architect,cn=roles,cn=accounts,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Security Architect 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG Security Architect 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=Security Architect,cn=roles,cn=accounts,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Security Architect 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG Security Architect 2019-01-17T11:00:48Z ERROR Parent DN of cn=Security Architect,cn=roles,cn=accounts,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=Delegation Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=Delegation Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG add: 'cn=Security Architect,cn=roles,cn=accounts,dc=local' to member, current value [] 2019-01-17T11:00:48Z DEBUG add: updated value [u'cn=Security Architect,cn=roles,cn=accounts,dc=local'] 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=Delegation Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=local 2019-01-17T11:00:48Z ERROR Parent DN of cn=Delegation Administrator,cn=privileges,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=Replication Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=Replication Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG add: 'cn=ipaservers,cn=hostgroups,cn=accounts,dc=local' to member, current value [] 2019-01-17T11:00:48Z DEBUG add: updated value [u'cn=ipaservers,cn=hostgroups,cn=accounts,dc=local'] 2019-01-17T11:00:48Z DEBUG add: 'cn=Security Architect,cn=roles,cn=accounts,dc=local' to member, current value [u'cn=ipaservers,cn=hostgroups,cn=accounts,dc=local'] 2019-01-17T11:00:48Z DEBUG add: updated value [u'cn=ipaservers,cn=hostgroups,cn=accounts,dc=local', u'cn=Security Architect,cn=roles,cn=accounts,dc=local'] 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=Replication Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=ipaservers,cn=hostgroups,cn=accounts,dc=local 2019-01-17T11:00:48Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=local 2019-01-17T11:00:48Z ERROR Parent DN of cn=Replication Administrators,cn=privileges,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG add: 'cn=Security Architect,cn=roles,cn=accounts,dc=local' to member, current value [] 2019-01-17T11:00:48Z DEBUG add: updated value [u'cn=Security Architect,cn=roles,cn=accounts,dc=local'] 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=local 2019-01-17T11:00:48Z ERROR Parent DN of cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG add: 'cn=Security Architect,cn=roles,cn=accounts,dc=local' to member, current value [] 2019-01-17T11:00:48Z DEBUG add: updated value [u'cn=Security Architect,cn=roles,cn=accounts,dc=local'] 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=local 2019-01-17T11:00:48Z ERROR Parent DN of cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=Enrollment Administrator,cn=roles,cn=accounts,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=Enrollment Administrator,cn=roles,cn=accounts,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Enrollment Administrator 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG Enrollment Administrator responsible for client(host) enrollment 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=Enrollment Administrator,cn=roles,cn=accounts,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG groupofnames 2019-01-17T11:00:48Z DEBUG nestedgroup 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG Enrollment Administrator 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG Enrollment Administrator responsible for client(host) enrollment 2019-01-17T11:00:48Z ERROR Parent DN of cn=Enrollment Administrator,cn=roles,cn=accounts,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=Host Enrollment,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=Host Enrollment,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG add: 'cn=Enrollment Administrator,cn=roles,cn=accounts,dc=local' to member, current value [] 2019-01-17T11:00:48Z DEBUG add: updated value [u'cn=Enrollment Administrator,cn=roles,cn=accounts,dc=local'] 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=Host Enrollment,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=Enrollment Administrator,cn=roles,cn=accounts,dc=local 2019-01-17T11:00:48Z ERROR Parent DN of cn=Host Enrollment,cn=privileges,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG Parsing update file '/usr/share/ipa/updates/50-7_bit_check.update' 2019-01-17T11:00:48Z DEBUG Updating existing entry: cn=7-bit check,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:48Z DEBUG NS7bitAttr 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG 7-bit check 2019-01-17T11:00:48Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:48Z DEBUG 1.3.8.4 2019-01-17T11:00:48Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:48Z DEBUG NS7bitAttr_Init 2019-01-17T11:00:48Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:48Z DEBUG Enforce 7-bit clean attribute values 2019-01-17T11:00:48Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:48Z DEBUG libattr-unique-plugin 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG nsSlapdPlugin 2019-01-17T11:00:48Z DEBUG extensibleObject 2019-01-17T11:00:48Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:48Z DEBUG database 2019-01-17T11:00:48Z DEBUG nsslapd-pluginarg0: 2019-01-17T11:00:48Z DEBUG uid 2019-01-17T11:00:48Z DEBUG nsslapd-pluginarg3: 2019-01-17T11:00:48Z DEBUG dc=local 2019-01-17T11:00:48Z DEBUG nsslapd-pluginarg2: 2019-01-17T11:00:48Z DEBUG , 2019-01-17T11:00:48Z DEBUG nsslapd-pluginarg1: 2019-01-17T11:00:48Z DEBUG mail 2019-01-17T11:00:48Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:48Z DEBUG betxnpreoperation 2019-01-17T11:00:48Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:48Z DEBUG 389 Project 2019-01-17T11:00:48Z DEBUG replace: userpassword not found, skipping 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:48Z DEBUG NS7bitAttr 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG 7-bit check 2019-01-17T11:00:48Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:48Z DEBUG 1.3.8.4 2019-01-17T11:00:48Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:48Z DEBUG NS7bitAttr_Init 2019-01-17T11:00:48Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:48Z DEBUG Enforce 7-bit clean attribute values 2019-01-17T11:00:48Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:48Z DEBUG on 2019-01-17T11:00:48Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:48Z DEBUG libattr-unique-plugin 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG nsSlapdPlugin 2019-01-17T11:00:48Z DEBUG extensibleObject 2019-01-17T11:00:48Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:48Z DEBUG database 2019-01-17T11:00:48Z DEBUG nsslapd-pluginarg0: 2019-01-17T11:00:48Z DEBUG uid 2019-01-17T11:00:48Z DEBUG nsslapd-pluginarg3: 2019-01-17T11:00:48Z DEBUG dc=local 2019-01-17T11:00:48Z DEBUG nsslapd-pluginarg2: 2019-01-17T11:00:48Z DEBUG , 2019-01-17T11:00:48Z DEBUG nsslapd-pluginarg1: 2019-01-17T11:00:48Z DEBUG mail 2019-01-17T11:00:48Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:48Z DEBUG betxnpreoperation 2019-01-17T11:00:48Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:48Z DEBUG 389 Project 2019-01-17T11:00:48Z DEBUG [] 2019-01-17T11:00:48Z DEBUG Updated 0 2019-01-17T11:00:48Z DEBUG Done 2019-01-17T11:00:48Z DEBUG Parsing update file '/usr/share/ipa/updates/50-dogtag10-migration.update' 2019-01-17T11:00:48Z DEBUG New entry: cn=aclResources,o=ipaca 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=aclResources,o=ipaca 2019-01-17T11:00:48Z DEBUG addifexist: 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout' to resourceACLS, current value [] 2019-01-17T11:00:48Z DEBUG addifexist: 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations' to resourceACLS, current value [] 2019-01-17T11:00:48Z DEBUG addifexist: 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations' to resourceACLS, current value [] 2019-01-17T11:00:48Z DEBUG addifexist: 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations' to resourceACLS, current value [] 2019-01-17T11:00:48Z DEBUG addifexist: 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations' to resourceACLS, current value [] 2019-01-17T11:00:48Z DEBUG replace: certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group":Anybody is allowed to read domain.xml but only Subsystem group is allowed to modify the domain.xml not found, skipping 2019-01-17T11:00:48Z DEBUG replace: certServer.ca.connectorInfo:read,modify:allow (modify,read) group="Enterprise KRA Administrators":Only Enterprise Administrators are allowed to update the connector information not found, skipping 2019-01-17T11:00:48Z DEBUG addifexist: 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles' to resourceACLS, current value [] 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=aclResources,o=ipaca 2019-01-17T11:00:48Z DEBUG Parsing update file '/usr/share/ipa/updates/50-externalmembers.update' 2019-01-17T11:00:48Z DEBUG Updating existing entry: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:00:48Z DEBUG objectclass=posixGroup 2019-01-17T11:00:48Z DEBUG gidNumber=%{gidNumber} 2019-01-17T11:00:48Z DEBUG memberUid=%{memberUid} 2019-01-17T11:00:48Z DEBUG memberUid=%deref_r("member","uid") 2019-01-17T11:00:48Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:00:48Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","") 2019-01-17T11:00:48Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2019-01-17T11:00:48Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG groups 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG extensibleObject 2019-01-17T11:00:48Z DEBUG schema-compat-container-rdn: 2019-01-17T11:00:48Z DEBUG cn=groups 2019-01-17T11:00:48Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:00:48Z DEBUG dc=local 2019-01-17T11:00:48Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:00:48Z DEBUG cn=%{cn} 2019-01-17T11:00:48Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:00:48Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG schema-compat-search-filter: 2019-01-17T11:00:48Z DEBUG objectclass=posixGroup 2019-01-17T11:00:48Z DEBUG schema-compat-search-base: 2019-01-17T11:00:48Z DEBUG cn=groups, cn=accounts, dc=local 2019-01-17T11:00:48Z DEBUG schema-compat-container-group: 2019-01-17T11:00:48Z DEBUG cn=compat, dc=local 2019-01-17T11:00:48Z DEBUG addifexist: 'ipaexternalmember=%deref_r("member","ipaexternalmember")' to schema-compat-entry-attribute, current value [u'objectclass=posixGroup', u'gidNumber=%{gidNumber}', u'memberUid=%{memberUid}', u'memberUid=%deref_r("member","uid")', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")'] 2019-01-17T11:00:48Z DEBUG addifexist: set schema-compat-entry-attribute to [u'objectclass=posixGroup', u'gidNumber=%{gidNumber}', u'memberUid=%{memberUid}', u'memberUid=%deref_r("member","uid")', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'ipaexternalmember=%deref_r("member","ipaexternalmember")'] 2019-01-17T11:00:48Z DEBUG addifexist: 'objectclass=ipaexternalgroup' to schema-compat-entry-attribute, current value [u'objectclass=posixGroup', u'gidNumber=%{gidNumber}', u'memberUid=%{memberUid}', u'memberUid=%deref_r("member","uid")', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'ipaexternalmember=%deref_r("member","ipaexternalmember")'] 2019-01-17T11:00:48Z DEBUG addifexist: set schema-compat-entry-attribute to [u'objectclass=posixGroup', u'gidNumber=%{gidNumber}', u'memberUid=%{memberUid}', u'memberUid=%deref_r("member","uid")', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'ipaexternalmember=%deref_r("member","ipaexternalmember")', u'objectclass=ipaexternalgroup'] 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:00:48Z DEBUG objectclass=posixGroup 2019-01-17T11:00:48Z DEBUG gidNumber=%{gidNumber} 2019-01-17T11:00:48Z DEBUG memberUid=%{memberUid} 2019-01-17T11:00:48Z DEBUG memberUid=%deref_r("member","uid") 2019-01-17T11:00:48Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:00:48Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","") 2019-01-17T11:00:48Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2019-01-17T11:00:48Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:00:48Z DEBUG ipaexternalmember=%deref_r("member","ipaexternalmember") 2019-01-17T11:00:48Z DEBUG objectclass=ipaexternalgroup 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG groups 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG extensibleObject 2019-01-17T11:00:48Z DEBUG schema-compat-container-rdn: 2019-01-17T11:00:48Z DEBUG cn=groups 2019-01-17T11:00:48Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:00:48Z DEBUG dc=local 2019-01-17T11:00:48Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:48Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:00:48Z DEBUG cn=%{cn} 2019-01-17T11:00:48Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:00:48Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG schema-compat-search-filter: 2019-01-17T11:00:48Z DEBUG objectclass=posixGroup 2019-01-17T11:00:48Z DEBUG schema-compat-search-base: 2019-01-17T11:00:48Z DEBUG cn=groups, cn=accounts, dc=local 2019-01-17T11:00:48Z DEBUG schema-compat-container-group: 2019-01-17T11:00:48Z DEBUG cn=compat, dc=local 2019-01-17T11:00:48Z DEBUG [(0, u'schema-compat-entry-attribute', [u'ipaexternalmember=%deref_r("member","ipaexternalmember")', u'objectclass=ipaexternalgroup'])] 2019-01-17T11:00:48Z DEBUG Updated 1 2019-01-17T11:00:48Z DEBUG Done 2019-01-17T11:00:48Z DEBUG Parsing update file '/usr/share/ipa/updates/50-groupuuid.update' 2019-01-17T11:00:48Z DEBUG New entry: cn=admins,cn=groups,cn=accounts,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=admins,cn=groups,cn=accounts,dc=local 2019-01-17T11:00:48Z DEBUG add: 'ipaobject' to objectclass, current value [] 2019-01-17T11:00:48Z DEBUG add: updated value [u'ipaobject'] 2019-01-17T11:00:48Z DEBUG addifnew: 'autogenerate' to ipaUniqueID, current value [] 2019-01-17T11:00:48Z DEBUG addifnew: set ipaUniqueID to [u'autogenerate'] 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=admins,cn=groups,cn=accounts,dc=local 2019-01-17T11:00:48Z DEBUG objectclass: 2019-01-17T11:00:48Z DEBUG ipaobject 2019-01-17T11:00:48Z DEBUG ipaUniqueID: 2019-01-17T11:00:48Z DEBUG autogenerate 2019-01-17T11:00:48Z ERROR Parent DN of cn=admins,cn=groups,cn=accounts,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=ipausers,cn=groups,cn=accounts,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=ipausers,cn=groups,cn=accounts,dc=local 2019-01-17T11:00:48Z DEBUG add: 'ipaobject' to objectclass, current value [] 2019-01-17T11:00:48Z DEBUG add: updated value [u'ipaobject'] 2019-01-17T11:00:48Z DEBUG addifnew: 'autogenerate' to ipaUniqueID, current value [] 2019-01-17T11:00:48Z DEBUG addifnew: set ipaUniqueID to [u'autogenerate'] 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=ipausers,cn=groups,cn=accounts,dc=local 2019-01-17T11:00:48Z DEBUG objectclass: 2019-01-17T11:00:48Z DEBUG ipaobject 2019-01-17T11:00:48Z DEBUG ipaUniqueID: 2019-01-17T11:00:48Z DEBUG autogenerate 2019-01-17T11:00:48Z ERROR Parent DN of cn=ipausers,cn=groups,cn=accounts,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=editors,cn=groups,cn=accounts,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=editors,cn=groups,cn=accounts,dc=local 2019-01-17T11:00:48Z DEBUG add: 'ipaobject' to objectclass, current value [] 2019-01-17T11:00:48Z DEBUG add: updated value [u'ipaobject'] 2019-01-17T11:00:48Z DEBUG addifnew: 'autogenerate' to ipaUniqueID, current value [] 2019-01-17T11:00:48Z DEBUG addifnew: set ipaUniqueID to [u'autogenerate'] 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=editors,cn=groups,cn=accounts,dc=local 2019-01-17T11:00:48Z DEBUG objectclass: 2019-01-17T11:00:48Z DEBUG ipaobject 2019-01-17T11:00:48Z DEBUG ipaUniqueID: 2019-01-17T11:00:48Z DEBUG autogenerate 2019-01-17T11:00:48Z ERROR Parent DN of cn=editors,cn=groups,cn=accounts,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG Parsing update file '/usr/share/ipa/updates/50-hbacservice.update' 2019-01-17T11:00:48Z DEBUG New entry: cn=crond,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=crond,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:00:48Z DEBUG objectclass: 2019-01-17T11:00:48Z DEBUG ipahbacservice 2019-01-17T11:00:48Z DEBUG ipaobject 2019-01-17T11:00:48Z DEBUG ipauniqueid: 2019-01-17T11:00:48Z DEBUG autogenerate 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG crond 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG crond 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=crond,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:00:48Z DEBUG objectclass: 2019-01-17T11:00:48Z DEBUG ipahbacservice 2019-01-17T11:00:48Z DEBUG ipaobject 2019-01-17T11:00:48Z DEBUG ipauniqueid: 2019-01-17T11:00:48Z DEBUG autogenerate 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG crond 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG crond 2019-01-17T11:00:48Z ERROR Parent DN of cn=crond,cn=hbacservices,cn=hbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=vsftpd,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=vsftpd,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:00:48Z DEBUG objectclass: 2019-01-17T11:00:48Z DEBUG ipahbacservice 2019-01-17T11:00:48Z DEBUG ipaobject 2019-01-17T11:00:48Z DEBUG ipauniqueid: 2019-01-17T11:00:48Z DEBUG autogenerate 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG vsftpd 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG vsftpd 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=vsftpd,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:00:48Z DEBUG objectclass: 2019-01-17T11:00:48Z DEBUG ipahbacservice 2019-01-17T11:00:48Z DEBUG ipaobject 2019-01-17T11:00:48Z DEBUG ipauniqueid: 2019-01-17T11:00:48Z DEBUG autogenerate 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG vsftpd 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG vsftpd 2019-01-17T11:00:48Z ERROR Parent DN of cn=vsftpd,cn=hbacservices,cn=hbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=proftpd,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=proftpd,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:00:48Z DEBUG objectclass: 2019-01-17T11:00:48Z DEBUG ipahbacservice 2019-01-17T11:00:48Z DEBUG ipaobject 2019-01-17T11:00:48Z DEBUG ipauniqueid: 2019-01-17T11:00:48Z DEBUG autogenerate 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG proftpd 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG proftpd 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=proftpd,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:00:48Z DEBUG objectclass: 2019-01-17T11:00:48Z DEBUG ipahbacservice 2019-01-17T11:00:48Z DEBUG ipaobject 2019-01-17T11:00:48Z DEBUG ipauniqueid: 2019-01-17T11:00:48Z DEBUG autogenerate 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG proftpd 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG proftpd 2019-01-17T11:00:48Z ERROR Parent DN of cn=proftpd,cn=hbacservices,cn=hbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=pure-ftpd,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=pure-ftpd,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:00:48Z DEBUG objectclass: 2019-01-17T11:00:48Z DEBUG ipahbacservice 2019-01-17T11:00:48Z DEBUG ipaobject 2019-01-17T11:00:48Z DEBUG ipauniqueid: 2019-01-17T11:00:48Z DEBUG autogenerate 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG pure-ftpd 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG pure-ftpd 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=pure-ftpd,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:00:48Z DEBUG objectclass: 2019-01-17T11:00:48Z DEBUG ipahbacservice 2019-01-17T11:00:48Z DEBUG ipaobject 2019-01-17T11:00:48Z DEBUG ipauniqueid: 2019-01-17T11:00:48Z DEBUG autogenerate 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG pure-ftpd 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG pure-ftpd 2019-01-17T11:00:48Z ERROR Parent DN of cn=pure-ftpd,cn=hbacservices,cn=hbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=gssftp,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=gssftp,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:00:48Z DEBUG objectclass: 2019-01-17T11:00:48Z DEBUG ipahbacservice 2019-01-17T11:00:48Z DEBUG ipaobject 2019-01-17T11:00:48Z DEBUG ipauniqueid: 2019-01-17T11:00:48Z DEBUG autogenerate 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG gssftp 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG gssftp 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=gssftp,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:00:48Z DEBUG objectclass: 2019-01-17T11:00:48Z DEBUG ipahbacservice 2019-01-17T11:00:48Z DEBUG ipaobject 2019-01-17T11:00:48Z DEBUG ipauniqueid: 2019-01-17T11:00:48Z DEBUG autogenerate 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG gssftp 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG gssftp 2019-01-17T11:00:48Z ERROR Parent DN of cn=gssftp,cn=hbacservices,cn=hbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG New entry: cn=ftp,cn=hbacservicegroups,cn=hbac,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=ftp,cn=hbacservicegroups,cn=hbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG ipaobject 2019-01-17T11:00:48Z DEBUG ipahbacservicegroup 2019-01-17T11:00:48Z DEBUG nestedGroup 2019-01-17T11:00:48Z DEBUG groupOfNames 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=ftp,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:00:48Z DEBUG cn=proftpd,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:00:48Z DEBUG cn=pure-ftpd,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:00:48Z DEBUG cn=vsftpd,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:00:48Z DEBUG cn=gssftp,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG Default group of ftp related services 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG ftp 2019-01-17T11:00:48Z DEBUG ipauniqueid: 2019-01-17T11:00:48Z DEBUG autogenerate 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=ftp,cn=hbacservicegroups,cn=hbac,dc=local 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG ipaobject 2019-01-17T11:00:48Z DEBUG ipahbacservicegroup 2019-01-17T11:00:48Z DEBUG nestedGroup 2019-01-17T11:00:48Z DEBUG groupOfNames 2019-01-17T11:00:48Z DEBUG top 2019-01-17T11:00:48Z DEBUG member: 2019-01-17T11:00:48Z DEBUG cn=ftp,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:00:48Z DEBUG cn=proftpd,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:00:48Z DEBUG cn=pure-ftpd,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:00:48Z DEBUG cn=vsftpd,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:00:48Z DEBUG cn=gssftp,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:00:48Z DEBUG description: 2019-01-17T11:00:48Z DEBUG Default group of ftp related services 2019-01-17T11:00:48Z DEBUG cn: 2019-01-17T11:00:48Z DEBUG ftp 2019-01-17T11:00:48Z DEBUG ipauniqueid: 2019-01-17T11:00:48Z DEBUG autogenerate 2019-01-17T11:00:48Z ERROR Parent DN of cn=ftp,cn=hbacservicegroups,cn=hbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG Parsing update file '/usr/share/ipa/updates/50-ipaconfig.update' 2019-01-17T11:00:48Z DEBUG New entry: cn=ipaConfig,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=ipaConfig,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG replace: guest_u:s0$xguest_u:s0$user_u:s0-s0:c0.c1023$staff_u:s0-s0:c0.c1023$unconfined_u:s0-s0:c0.c1023 not found, skipping 2019-01-17T11:00:48Z DEBUG add: 'unconfined_u:s0-s0:c0.c1023' to ipaSELinuxUserMapDefault, current value [] 2019-01-17T11:00:48Z DEBUG add: updated value [u'unconfined_u:s0-s0:c0.c1023'] 2019-01-17T11:00:48Z DEBUG add: 'ipasshuser' to ipaUserObjectClasses, current value [] 2019-01-17T11:00:48Z DEBUG add: updated value [u'ipasshuser'] 2019-01-17T11:00:48Z DEBUG remove: 'AllowLMhash' from ipaConfigString, current value [] 2019-01-17T11:00:48Z DEBUG remove: 'AllowLMhash' not in ipaConfigString 2019-01-17T11:00:48Z DEBUG add: 'ipaUserAuthTypeClass' to objectClass, current value [] 2019-01-17T11:00:48Z DEBUG add: updated value [u'ipaUserAuthTypeClass'] 2019-01-17T11:00:48Z DEBUG add: 'ipaNameResolutionData' to objectClass, current value [u'ipaUserAuthTypeClass'] 2019-01-17T11:00:48Z DEBUG add: updated value [u'ipaUserAuthTypeClass', u'ipaNameResolutionData'] 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=ipaConfig,cn=etc,dc=local 2019-01-17T11:00:48Z DEBUG ipaUserObjectClasses: 2019-01-17T11:00:48Z DEBUG ipasshuser 2019-01-17T11:00:48Z DEBUG objectClass: 2019-01-17T11:00:48Z DEBUG ipaUserAuthTypeClass 2019-01-17T11:00:48Z DEBUG ipaNameResolutionData 2019-01-17T11:00:48Z DEBUG ipaSELinuxUserMapDefault: 2019-01-17T11:00:48Z DEBUG unconfined_u:s0-s0:c0.c1023 2019-01-17T11:00:48Z ERROR Parent DN of cn=ipaConfig,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:48Z DEBUG Parsing update file '/usr/share/ipa/updates/50-krbenctypes.update' 2019-01-17T11:00:48Z DEBUG New entry: cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Initial value 2019-01-17T11:00:48Z DEBUG dn: cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:00:48Z DEBUG add: 'camellia128-cts-cmac:normal' to krbSupportedEncSaltTypes, current value [] 2019-01-17T11:00:48Z DEBUG add: updated value [u'camellia128-cts-cmac:normal'] 2019-01-17T11:00:48Z DEBUG add: 'camellia128-cts-cmac:special' to krbSupportedEncSaltTypes, current value [u'camellia128-cts-cmac:normal'] 2019-01-17T11:00:48Z DEBUG add: updated value [u'camellia128-cts-cmac:normal', u'camellia128-cts-cmac:special'] 2019-01-17T11:00:48Z DEBUG add: 'camellia256-cts-cmac:normal' to krbSupportedEncSaltTypes, current value [u'camellia128-cts-cmac:normal', u'camellia128-cts-cmac:special'] 2019-01-17T11:00:48Z DEBUG add: updated value [u'camellia128-cts-cmac:normal', u'camellia128-cts-cmac:special', u'camellia256-cts-cmac:normal'] 2019-01-17T11:00:48Z DEBUG add: 'camellia256-cts-cmac:special' to krbSupportedEncSaltTypes, current value [u'camellia128-cts-cmac:normal', u'camellia128-cts-cmac:special', u'camellia256-cts-cmac:normal'] 2019-01-17T11:00:48Z DEBUG add: updated value [u'camellia128-cts-cmac:normal', u'camellia128-cts-cmac:special', u'camellia256-cts-cmac:normal', u'camellia256-cts-cmac:special'] 2019-01-17T11:00:48Z DEBUG --------------------------------------------- 2019-01-17T11:00:48Z DEBUG Final value after applying updates 2019-01-17T11:00:48Z DEBUG dn: cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:00:48Z DEBUG krbSupportedEncSaltTypes: 2019-01-17T11:00:48Z DEBUG camellia128-cts-cmac:normal 2019-01-17T11:00:48Z DEBUG camellia128-cts-cmac:special 2019-01-17T11:00:48Z DEBUG camellia256-cts-cmac:normal 2019-01-17T11:00:48Z DEBUG camellia256-cts-cmac:special 2019-01-17T11:00:49Z ERROR Parent DN of cn=LOCAL,cn=kerberos,dc=local may not exist, cannot create the entry 2019-01-17T11:00:49Z DEBUG Parsing update file '/usr/share/ipa/updates/50-nis.update' 2019-01-17T11:00:49Z DEBUG Executing upgrade plugin: update_nis_configuration 2019-01-17T11:00:49Z DEBUG raw: update_nis_configuration 2019-01-17T11:00:49Z DEBUG Skipping NIS update, NIS Server is not configured 2019-01-17T11:00:49Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:00:49Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:00:49Z DEBUG Parsing update file '/usr/share/ipa/updates/55-pbacmemberof.update' 2019-01-17T11:00:49Z DEBUG New entry: cn=Update PBAC memberOf 1547722843,cn=memberof task,cn=tasks,cn=config 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=Update PBAC memberOf 1547722843,cn=memberof task,cn=tasks,cn=config 2019-01-17T11:00:49Z DEBUG add: 'top' to objectClass, current value [] 2019-01-17T11:00:49Z DEBUG add: updated value [u'top'] 2019-01-17T11:00:49Z DEBUG add: 'extensibleObject' to objectClass, current value [u'top'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'top', u'extensibleObject'] 2019-01-17T11:00:49Z DEBUG add: 'IPA PBAC memberOf 1547722843' to cn, current value [] 2019-01-17T11:00:49Z DEBUG add: updated value [u'IPA PBAC memberOf 1547722843'] 2019-01-17T11:00:49Z DEBUG add: 'cn=privileges,cn=pbac,dc=local' to basedn, current value [] 2019-01-17T11:00:49Z DEBUG add: updated value [u'cn=privileges,cn=pbac,dc=local'] 2019-01-17T11:00:49Z DEBUG add: '(objectclass=*)' to filter, current value [] 2019-01-17T11:00:49Z DEBUG add: updated value [u'(objectclass=*)'] 2019-01-17T11:00:49Z DEBUG add: '10' to ttl, current value [] 2019-01-17T11:00:49Z DEBUG add: updated value [u'10'] 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=Update PBAC memberOf 1547722843,cn=memberof task,cn=tasks,cn=config 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG filter: 2019-01-17T11:00:49Z DEBUG (objectclass=*) 2019-01-17T11:00:49Z DEBUG basedn: 2019-01-17T11:00:49Z DEBUG cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG IPA PBAC memberOf 1547722843 2019-01-17T11:00:49Z DEBUG ttl: 2019-01-17T11:00:49Z DEBUG 10 2019-01-17T11:00:49Z DEBUG New entry: cn=Update Role memberOf 1547722843,cn=memberof task,cn=tasks,cn=config 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=Update Role memberOf 1547722843,cn=memberof task,cn=tasks,cn=config 2019-01-17T11:00:49Z DEBUG add: 'top' to objectClass, current value [] 2019-01-17T11:00:49Z DEBUG add: updated value [u'top'] 2019-01-17T11:00:49Z DEBUG add: 'extensibleObject' to objectClass, current value [u'top'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'top', u'extensibleObject'] 2019-01-17T11:00:49Z DEBUG add: 'Update Role memberOf 1547722843' to cn, current value [] 2019-01-17T11:00:49Z DEBUG add: updated value [u'Update Role memberOf 1547722843'] 2019-01-17T11:00:49Z DEBUG add: 'cn=roles,cn=accounts,dc=local' to basedn, current value [] 2019-01-17T11:00:49Z DEBUG add: updated value [u'cn=roles,cn=accounts,dc=local'] 2019-01-17T11:00:49Z DEBUG add: '(objectclass=*)' to filter, current value [] 2019-01-17T11:00:49Z DEBUG add: updated value [u'(objectclass=*)'] 2019-01-17T11:00:49Z DEBUG add: '10' to ttl, current value [] 2019-01-17T11:00:49Z DEBUG add: updated value [u'10'] 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=Update Role memberOf 1547722843,cn=memberof task,cn=tasks,cn=config 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG filter: 2019-01-17T11:00:49Z DEBUG (objectclass=*) 2019-01-17T11:00:49Z DEBUG basedn: 2019-01-17T11:00:49Z DEBUG cn=roles,cn=accounts,dc=local 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG Update Role memberOf 1547722843 2019-01-17T11:00:49Z DEBUG ttl: 2019-01-17T11:00:49Z DEBUG 10 2019-01-17T11:00:49Z DEBUG Parsing update file '/usr/share/ipa/updates/59-trusts-sysacount.update' 2019-01-17T11:00:49Z DEBUG New entry: cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG GroupOfNames 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG adtrust agents 2019-01-17T11:00:49Z DEBUG add: 'nestedgroup' to objectClass, current value [u'GroupOfNames', u'top'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'GroupOfNames', u'top', u'nestedgroup'] 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG GroupOfNames 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG nestedgroup 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG adtrust agents 2019-01-17T11:00:49Z ERROR Parent DN of cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:49Z DEBUG Parsing update file '/usr/share/ipa/updates/60-trusts.update' 2019-01-17T11:00:49Z DEBUG New entry: cn=trust admins,cn=groups,cn=accounts,dc=local 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=trust admins,cn=groups,cn=accounts,dc=local 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG trust admins 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG groupofnames 2019-01-17T11:00:49Z DEBUG ipausergroup 2019-01-17T11:00:49Z DEBUG nestedgroup 2019-01-17T11:00:49Z DEBUG ipaobject 2019-01-17T11:00:49Z DEBUG member: 2019-01-17T11:00:49Z DEBUG uid=admin,cn=users,cn=accounts,dc=local 2019-01-17T11:00:49Z DEBUG ipaUniqueID: 2019-01-17T11:00:49Z DEBUG autogenerate 2019-01-17T11:00:49Z DEBUG nsAccountLock: 2019-01-17T11:00:49Z DEBUG FALSE 2019-01-17T11:00:49Z DEBUG description: 2019-01-17T11:00:49Z DEBUG Trusts administrators group 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=trust admins,cn=groups,cn=accounts,dc=local 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG trust admins 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG groupofnames 2019-01-17T11:00:49Z DEBUG ipausergroup 2019-01-17T11:00:49Z DEBUG nestedgroup 2019-01-17T11:00:49Z DEBUG ipaobject 2019-01-17T11:00:49Z DEBUG member: 2019-01-17T11:00:49Z DEBUG uid=admin,cn=users,cn=accounts,dc=local 2019-01-17T11:00:49Z DEBUG ipaUniqueID: 2019-01-17T11:00:49Z DEBUG autogenerate 2019-01-17T11:00:49Z DEBUG nsAccountLock: 2019-01-17T11:00:49Z DEBUG FALSE 2019-01-17T11:00:49Z DEBUG description: 2019-01-17T11:00:49Z DEBUG Trusts administrators group 2019-01-17T11:00:49Z ERROR Parent DN of cn=trust admins,cn=groups,cn=accounts,dc=local may not exist, cannot create the entry 2019-01-17T11:00:49Z DEBUG New entry: cn=ADTrust Agents,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=ADTrust Agents,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG groupofnames 2019-01-17T11:00:49Z DEBUG nestedgroup 2019-01-17T11:00:49Z DEBUG member: 2019-01-17T11:00:49Z DEBUG cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG ADTrust Agents 2019-01-17T11:00:49Z DEBUG description: 2019-01-17T11:00:49Z DEBUG System accounts able to access trust information 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=ADTrust Agents,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG groupofnames 2019-01-17T11:00:49Z DEBUG nestedgroup 2019-01-17T11:00:49Z DEBUG member: 2019-01-17T11:00:49Z DEBUG cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG ADTrust Agents 2019-01-17T11:00:49Z DEBUG description: 2019-01-17T11:00:49Z DEBUG System accounts able to access trust information 2019-01-17T11:00:49Z ERROR Parent DN of cn=ADTrust Agents,cn=privileges,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:49Z DEBUG New entry: cn=trusts,dc=local 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=trusts,dc=local 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG nsContainer 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG trusts 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=trusts,dc=local 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG nsContainer 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG trusts 2019-01-17T11:00:49Z ERROR Parent DN of cn=trusts,dc=local may not exist, cannot create the entry 2019-01-17T11:00:49Z DEBUG New entry: cn=trusts,dc=local 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=trusts,dc=local 2019-01-17T11:00:49Z DEBUG add: '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)' to aci, current value [] 2019-01-17T11:00:49Z DEBUG add: updated value [u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2019-01-17T11:00:49Z DEBUG add: '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)' to aci, current value [u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)'] 2019-01-17T11:00:49Z DEBUG add: '(target = "ldap:///cn=trusts,dc=local")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)' to aci, current value [u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)', u'(target = "ldap:///cn=trusts,dc=local")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)'] 2019-01-17T11:00:49Z DEBUG replace: updated value [u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)', u'(target = "ldap:///cn=trusts,dc=local")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)'] 2019-01-17T11:00:49Z DEBUG replace: (target = "ldap:///cn=trusts,dc=local")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=local";) not found, skipping 2019-01-17T11:00:49Z DEBUG add: '(target = "ldap:///cn=trusts,dc=local")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=local";)' to aci, current value [u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)', u'(target = "ldap:///cn=trusts,dc=local")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)', u'(target = "ldap:///cn=trusts,dc=local")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)', u'(target = "ldap:///cn=trusts,dc=local")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=trusts,dc=local 2019-01-17T11:00:49Z DEBUG aci: 2019-01-17T11:00:49Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2019-01-17T11:00:49Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";) 2019-01-17T11:00:49Z DEBUG (target = "ldap:///cn=trusts,dc=local")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";) 2019-01-17T11:00:49Z DEBUG (target = "ldap:///cn=trusts,dc=local")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:00:49Z ERROR Parent DN of cn=trusts,dc=local may not exist, cannot create the entry 2019-01-17T11:00:49Z DEBUG New entry: dc=local 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: dc=local 2019-01-17T11:00:49Z DEBUG add: '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)' to aci, current value [] 2019-01-17T11:00:49Z DEBUG add: updated value [u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)'] 2019-01-17T11:00:49Z DEBUG remove: '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read NT passwords"; allow (read) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)' from aci, current value [u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)'] 2019-01-17T11:00:49Z DEBUG remove: '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read NT passwords"; allow (read) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)' not in aci 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: dc=local 2019-01-17T11:00:49Z DEBUG aci: 2019-01-17T11:00:49Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";) 2019-01-17T11:00:49Z ERROR Add failure missing required attribute "objectclass" 2019-01-17T11:00:49Z DEBUG New entry: cn=ipaConfig,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=ipaConfig,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG addifnew: 'MS-PAC' to ipaKrbAuthzData, current value [] 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=ipaConfig,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG Parsing update file '/usr/share/ipa/updates/61-trusts-s4u2proxy.update' 2019-01-17T11:00:49Z DEBUG New entry: cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG groupOfPrincipals 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG ipa-cifs-delegation-targets 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG groupOfPrincipals 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG ipa-cifs-delegation-targets 2019-01-17T11:00:49Z ERROR Parent DN of cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:49Z DEBUG New entry: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG add: 'cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=local' to ipaAllowedTarget, current value [] 2019-01-17T11:00:49Z DEBUG add: updated value [u'cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=local'] 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG ipaAllowedTarget: 2019-01-17T11:00:49Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:00:49Z ERROR Parent DN of cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:49Z DEBUG Parsing update file '/usr/share/ipa/updates/62-ranges.update' 2019-01-17T11:00:49Z DEBUG New entry: cn=ranges,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=ranges,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG nsContainer 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG ranges 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=ranges,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG nsContainer 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG ranges 2019-01-17T11:00:49Z ERROR Parent DN of cn=ranges,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:49Z DEBUG Updating existing entry: cn=IPA Range-Check,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=IPA Range-Check,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:49Z DEBUG IPA ID range check plugin 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG IPA Range-Check 2019-01-17T11:00:49Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:49Z DEBUG FreeIPA/1.0 2019-01-17T11:00:49Z DEBUG nsslapd-basedn: 2019-01-17T11:00:49Z DEBUG dc=local 2019-01-17T11:00:49Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:49Z DEBUG Check if newly added or modified ID ranges do not overlap with existing ones 2019-01-17T11:00:49Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:49Z DEBUG on 2019-01-17T11:00:49Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:49Z DEBUG libipa_range_check 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG nsSlapdPlugin 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:49Z DEBUG database 2019-01-17T11:00:49Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:49Z DEBUG FreeIPA project 2019-01-17T11:00:49Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:49Z DEBUG preoperation 2019-01-17T11:00:49Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:49Z DEBUG ipa_range_check_init 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=IPA Range-Check,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:49Z DEBUG IPA ID range check plugin 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG IPA Range-Check 2019-01-17T11:00:49Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:49Z DEBUG FreeIPA/1.0 2019-01-17T11:00:49Z DEBUG nsslapd-basedn: 2019-01-17T11:00:49Z DEBUG dc=local 2019-01-17T11:00:49Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:49Z DEBUG Check if newly added or modified ID ranges do not overlap with existing ones 2019-01-17T11:00:49Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:49Z DEBUG on 2019-01-17T11:00:49Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:49Z DEBUG libipa_range_check 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG nsSlapdPlugin 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:00:49Z DEBUG database 2019-01-17T11:00:49Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:49Z DEBUG FreeIPA project 2019-01-17T11:00:49Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:49Z DEBUG preoperation 2019-01-17T11:00:49Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:49Z DEBUG ipa_range_check_init 2019-01-17T11:00:49Z DEBUG [] 2019-01-17T11:00:49Z DEBUG Updated 0 2019-01-17T11:00:49Z DEBUG Done 2019-01-17T11:00:49Z DEBUG Updating existing entry: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG dnaScope: 2019-01-17T11:00:49Z DEBUG dc=local 2019-01-17T11:00:49Z DEBUG dnaThreshold: 2019-01-17T11:00:49Z DEBUG 500 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG Posix IDs 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG aci: 2019-01-17T11:00:49Z DEBUG (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:49Z DEBUG (targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:49Z DEBUG dnaMagicRegen: 2019-01-17T11:00:49Z DEBUG -1 2019-01-17T11:00:49Z DEBUG dnaNextValue: 2019-01-17T11:00:49Z DEBUG 353600000 2019-01-17T11:00:49Z DEBUG dnaExcludeScope: 2019-01-17T11:00:49Z DEBUG cn=provisioning,dc=local 2019-01-17T11:00:49Z DEBUG dnaFilter: 2019-01-17T11:00:49Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2019-01-17T11:00:49Z DEBUG dnaType: 2019-01-17T11:00:49Z DEBUG uidNumber 2019-01-17T11:00:49Z DEBUG gidNumber 2019-01-17T11:00:49Z DEBUG dnaMaxValue: 2019-01-17T11:00:49Z DEBUG 353799999 2019-01-17T11:00:49Z DEBUG dnaSharedCfgDN: 2019-01-17T11:00:49Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG replace: (|(objectclass=posixAccount)(objectClass=posixGroup)) not found, skipping 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG dnaScope: 2019-01-17T11:00:49Z DEBUG dc=local 2019-01-17T11:00:49Z DEBUG dnaThreshold: 2019-01-17T11:00:49Z DEBUG 500 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG Posix IDs 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG aci: 2019-01-17T11:00:49Z DEBUG (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:49Z DEBUG (targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:00:49Z DEBUG dnaMagicRegen: 2019-01-17T11:00:49Z DEBUG -1 2019-01-17T11:00:49Z DEBUG dnaNextValue: 2019-01-17T11:00:49Z DEBUG 353600000 2019-01-17T11:00:49Z DEBUG dnaExcludeScope: 2019-01-17T11:00:49Z DEBUG cn=provisioning,dc=local 2019-01-17T11:00:49Z DEBUG dnaFilter: 2019-01-17T11:00:49Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2019-01-17T11:00:49Z DEBUG dnaType: 2019-01-17T11:00:49Z DEBUG uidNumber 2019-01-17T11:00:49Z DEBUG gidNumber 2019-01-17T11:00:49Z DEBUG dnaMaxValue: 2019-01-17T11:00:49Z DEBUG 353799999 2019-01-17T11:00:49Z DEBUG dnaSharedCfgDN: 2019-01-17T11:00:49Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG [] 2019-01-17T11:00:49Z DEBUG Updated 0 2019-01-17T11:00:49Z DEBUG Done 2019-01-17T11:00:49Z DEBUG Parsing update file '/usr/share/ipa/updates/71-idviews-sasl-mapping.update' 2019-01-17T11:00:49Z DEBUG Updating existing entry: cn=ID Overridden Principal,cn=mapping,cn=sasl,cn=config 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=ID Overridden Principal,cn=mapping,cn=sasl,cn=config 2019-01-17T11:00:49Z DEBUG nsSaslMapPriority: 2019-01-17T11:00:49Z DEBUG 20 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG ID Overridden Principal 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG nsSaslMapping 2019-01-17T11:00:49Z DEBUG nsSaslMapRegexString: 2019-01-17T11:00:49Z DEBUG \(.*\)@\(.*\) 2019-01-17T11:00:49Z DEBUG nsSaslMapBaseDNTemplate: 2019-01-17T11:00:49Z DEBUG cn=default trust view,cn=views,cn=accounts,dc=local 2019-01-17T11:00:49Z DEBUG nsSaslMapFilterTemplate: 2019-01-17T11:00:49Z DEBUG (&(ipaoriginaluid=\1@\2)(objectclass=ipaUserOverride)) 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=ID Overridden Principal,cn=mapping,cn=sasl,cn=config 2019-01-17T11:00:49Z DEBUG nsSaslMapPriority: 2019-01-17T11:00:49Z DEBUG 20 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG ID Overridden Principal 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG nsSaslMapping 2019-01-17T11:00:49Z DEBUG nsSaslMapRegexString: 2019-01-17T11:00:49Z DEBUG \(.*\)@\(.*\) 2019-01-17T11:00:49Z DEBUG nsSaslMapBaseDNTemplate: 2019-01-17T11:00:49Z DEBUG cn=default trust view,cn=views,cn=accounts,dc=local 2019-01-17T11:00:49Z DEBUG nsSaslMapFilterTemplate: 2019-01-17T11:00:49Z DEBUG (&(ipaoriginaluid=\1@\2)(objectclass=ipaUserOverride)) 2019-01-17T11:00:49Z DEBUG [] 2019-01-17T11:00:49Z DEBUG Updated 0 2019-01-17T11:00:49Z DEBUG Done 2019-01-17T11:00:49Z DEBUG Parsing update file '/usr/share/ipa/updates/71-idviews.update' 2019-01-17T11:00:49Z DEBUG New entry: cn=views,cn=accounts,dc=local 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=views,cn=accounts,dc=local 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG nsContainer 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG views 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=views,cn=accounts,dc=local 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG nsContainer 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG views 2019-01-17T11:00:49Z ERROR Parent DN of cn=views,cn=accounts,dc=local may not exist, cannot create the entry 2019-01-17T11:00:49Z DEBUG Parsing update file '/usr/share/ipa/updates/72-domainlevels.update' 2019-01-17T11:00:49Z DEBUG New entry: cn=Domain Level,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=Domain Level,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG nsContainer 2019-01-17T11:00:49Z DEBUG ipaDomainLevelConfig 2019-01-17T11:00:49Z DEBUG ipaDomainLevel: 2019-01-17T11:00:49Z DEBUG 0 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=Domain Level,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG nsContainer 2019-01-17T11:00:49Z DEBUG ipaDomainLevelConfig 2019-01-17T11:00:49Z DEBUG ipaDomainLevel: 2019-01-17T11:00:49Z DEBUG 0 2019-01-17T11:00:49Z ERROR Parent DN of cn=Domain Level,cn=ipa,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:49Z DEBUG New entry: cn=centos75.local,cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=centos75.local,cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG add: 'ipaConfigObject' to objectClass, current value [] 2019-01-17T11:00:49Z DEBUG add: updated value [u'ipaConfigObject'] 2019-01-17T11:00:49Z DEBUG add: 'ipaSupportedDomainLevelConfig' to objectClass, current value [u'ipaConfigObject'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'ipaConfigObject', u'ipaSupportedDomainLevelConfig'] 2019-01-17T11:00:49Z DEBUG only: set ipaMinDomainLevel to '0', current value [] 2019-01-17T11:00:49Z DEBUG only: updated value [u'0'] 2019-01-17T11:00:49Z DEBUG only: set ipaMaxDomainLevel to '1', current value [] 2019-01-17T11:00:49Z DEBUG only: updated value [u'1'] 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=centos75.local,cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG ipaConfigObject 2019-01-17T11:00:49Z DEBUG ipaSupportedDomainLevelConfig 2019-01-17T11:00:49Z DEBUG ipaMaxDomainLevel: 2019-01-17T11:00:49Z DEBUG 1 2019-01-17T11:00:49Z DEBUG ipaMinDomainLevel: 2019-01-17T11:00:49Z DEBUG 0 2019-01-17T11:00:49Z ERROR Parent DN of cn=centos75.local,cn=masters,cn=ipa,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:49Z DEBUG Parsing update file '/usr/share/ipa/updates/73-certmap.update' 2019-01-17T11:00:49Z DEBUG New entry: cn=certmap,dc=local 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=certmap,dc=local 2019-01-17T11:00:49Z DEBUG objectclass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG nsContainer 2019-01-17T11:00:49Z DEBUG ipaCertMapConfigObject 2019-01-17T11:00:49Z DEBUG ipaCertMapPromptUsername: 2019-01-17T11:00:49Z DEBUG FALSE 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG certmap 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=certmap,dc=local 2019-01-17T11:00:49Z DEBUG objectclass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG nsContainer 2019-01-17T11:00:49Z DEBUG ipaCertMapConfigObject 2019-01-17T11:00:49Z DEBUG ipaCertMapPromptUsername: 2019-01-17T11:00:49Z DEBUG FALSE 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG certmap 2019-01-17T11:00:49Z ERROR Parent DN of cn=certmap,dc=local may not exist, cannot create the entry 2019-01-17T11:00:49Z DEBUG New entry: cn=certmaprules,cn=certmap,dc=local 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=certmaprules,cn=certmap,dc=local 2019-01-17T11:00:49Z DEBUG objectclass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG nsContainer 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG certmaprules 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=certmaprules,cn=certmap,dc=local 2019-01-17T11:00:49Z DEBUG objectclass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG nsContainer 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG certmaprules 2019-01-17T11:00:49Z ERROR Parent DN of cn=certmaprules,cn=certmap,dc=local may not exist, cannot create the entry 2019-01-17T11:00:49Z DEBUG New entry: cn=Certificate Identity Mapping Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=Certificate Identity Mapping Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG groupofnames 2019-01-17T11:00:49Z DEBUG nestedgroup 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG Certificate Identity Mapping Administrators 2019-01-17T11:00:49Z DEBUG description: 2019-01-17T11:00:49Z DEBUG Certificate Identity Mapping Administrators 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=Certificate Identity Mapping Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG groupofnames 2019-01-17T11:00:49Z DEBUG nestedgroup 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG Certificate Identity Mapping Administrators 2019-01-17T11:00:49Z DEBUG description: 2019-01-17T11:00:49Z DEBUG Certificate Identity Mapping Administrators 2019-01-17T11:00:49Z ERROR Parent DN of cn=Certificate Identity Mapping Administrators,cn=privileges,cn=pbac,dc=local may not exist, cannot create the entry 2019-01-17T11:00:49Z DEBUG New entry: dc=local 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: dc=local 2019-01-17T11:00:49Z DEBUG add: '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)' to aci, current value [] 2019-01-17T11:00:49Z DEBUG add: updated value [u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)'] 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: dc=local 2019-01-17T11:00:49Z DEBUG aci: 2019-01-17T11:00:49Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2019-01-17T11:00:49Z ERROR Add failure missing required attribute "objectclass" 2019-01-17T11:00:49Z DEBUG Parsing update file '/usr/share/ipa/updates/73-custodia.update' 2019-01-17T11:00:49Z DEBUG New entry: cn=custodia,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=custodia,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG nsContainer 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG custodia 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=custodia,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG nsContainer 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG custodia 2019-01-17T11:00:49Z ERROR Parent DN of cn=custodia,cn=ipa,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:49Z DEBUG New entry: cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG nsContainer 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG dogtag 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG nsContainer 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG dogtag 2019-01-17T11:00:49Z ERROR Parent DN of cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:49Z DEBUG Parsing update file '/usr/share/ipa/updates/73-winsync.update' 2019-01-17T11:00:49Z DEBUG New entry: uid=passsync,cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: uid=passsync,cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG addifexist: 'inetUser' to objectClass, current value [] 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: uid=passsync,cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG Parsing update file '/usr/share/ipa/updates/80-schema_compat.update' 2019-01-17T11:00:49Z DEBUG Updating existing entry: cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:00:49Z DEBUG on 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG Schema Compatibility 2019-01-17T11:00:49Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:49Z DEBUG none 2019-01-17T11:00:49Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:49Z DEBUG none 2019-01-17T11:00:49Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:49Z DEBUG off 2019-01-17T11:00:49Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:49Z DEBUG /usr/lib64/dirsrv/plugins/schemacompat-plugin.so 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG nsSlapdPlugin 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:49Z DEBUG none 2019-01-17T11:00:49Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:49Z DEBUG schema_compat_plugin_init 2019-01-17T11:00:49Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:00:49Z DEBUG 40 2019-01-17T11:00:49Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:49Z DEBUG object 2019-01-17T11:00:49Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:49Z DEBUG none 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:00:49Z DEBUG on 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG Schema Compatibility 2019-01-17T11:00:49Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:49Z DEBUG none 2019-01-17T11:00:49Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:49Z DEBUG none 2019-01-17T11:00:49Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:49Z DEBUG off 2019-01-17T11:00:49Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:49Z DEBUG /usr/lib64/dirsrv/plugins/schemacompat-plugin.so 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG nsSlapdPlugin 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:49Z DEBUG none 2019-01-17T11:00:49Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:49Z DEBUG schema_compat_plugin_init 2019-01-17T11:00:49Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:00:49Z DEBUG 40 2019-01-17T11:00:49Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:49Z DEBUG object 2019-01-17T11:00:49Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:49Z DEBUG none 2019-01-17T11:00:49Z DEBUG [] 2019-01-17T11:00:49Z DEBUG Updated 0 2019-01-17T11:00:49Z DEBUG Done 2019-01-17T11:00:49Z DEBUG Updating existing entry: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:00:49Z DEBUG objectclass=posixAccount 2019-01-17T11:00:49Z DEBUG gecos=%{cn} 2019-01-17T11:00:49Z DEBUG cn=%{cn} 2019-01-17T11:00:49Z DEBUG uidNumber=%{uidNumber} 2019-01-17T11:00:49Z DEBUG gidNumber=%{gidNumber} 2019-01-17T11:00:49Z DEBUG loginShell=%{loginShell} 2019-01-17T11:00:49Z DEBUG homeDirectory=%{homeDirectory} 2019-01-17T11:00:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:00:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","") 2019-01-17T11:00:49Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2019-01-17T11:00:49Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:00:49Z DEBUG uid=%{uid} 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG users 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG schema-compat-container-rdn: 2019-01-17T11:00:49Z DEBUG cn=users 2019-01-17T11:00:49Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:00:49Z DEBUG dc=local 2019-01-17T11:00:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:00:49Z DEBUG uid=%first("%{uid}") 2019-01-17T11:00:49Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:00:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-search-filter: 2019-01-17T11:00:49Z DEBUG objectclass=posixAccount 2019-01-17T11:00:49Z DEBUG schema-compat-search-base: 2019-01-17T11:00:49Z DEBUG cn=users, cn=accounts, dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-container-group: 2019-01-17T11:00:49Z DEBUG cn=compat, dc=local 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:00:49Z DEBUG objectclass=posixAccount 2019-01-17T11:00:49Z DEBUG gecos=%{cn} 2019-01-17T11:00:49Z DEBUG cn=%{cn} 2019-01-17T11:00:49Z DEBUG uidNumber=%{uidNumber} 2019-01-17T11:00:49Z DEBUG gidNumber=%{gidNumber} 2019-01-17T11:00:49Z DEBUG loginShell=%{loginShell} 2019-01-17T11:00:49Z DEBUG homeDirectory=%{homeDirectory} 2019-01-17T11:00:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:00:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","") 2019-01-17T11:00:49Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2019-01-17T11:00:49Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:00:49Z DEBUG uid=%{uid} 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG users 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG schema-compat-container-rdn: 2019-01-17T11:00:49Z DEBUG cn=users 2019-01-17T11:00:49Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:00:49Z DEBUG dc=local 2019-01-17T11:00:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:00:49Z DEBUG uid=%first("%{uid}") 2019-01-17T11:00:49Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:00:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-search-filter: 2019-01-17T11:00:49Z DEBUG objectclass=posixAccount 2019-01-17T11:00:49Z DEBUG schema-compat-search-base: 2019-01-17T11:00:49Z DEBUG cn=users, cn=accounts, dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-container-group: 2019-01-17T11:00:49Z DEBUG cn=compat, dc=local 2019-01-17T11:00:49Z DEBUG [] 2019-01-17T11:00:49Z DEBUG Updated 0 2019-01-17T11:00:49Z DEBUG Done 2019-01-17T11:00:49Z DEBUG Updating existing entry: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:00:49Z DEBUG objectclass=posixGroup 2019-01-17T11:00:49Z DEBUG gidNumber=%{gidNumber} 2019-01-17T11:00:49Z DEBUG memberUid=%{memberUid} 2019-01-17T11:00:49Z DEBUG memberUid=%deref_r("member","uid") 2019-01-17T11:00:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:00:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","") 2019-01-17T11:00:49Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2019-01-17T11:00:49Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:00:49Z DEBUG ipaexternalmember=%deref_r("member","ipaexternalmember") 2019-01-17T11:00:49Z DEBUG objectclass=ipaexternalgroup 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG groups 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG schema-compat-container-rdn: 2019-01-17T11:00:49Z DEBUG cn=groups 2019-01-17T11:00:49Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:00:49Z DEBUG dc=local 2019-01-17T11:00:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:00:49Z DEBUG cn=%{cn} 2019-01-17T11:00:49Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:00:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-search-filter: 2019-01-17T11:00:49Z DEBUG objectclass=posixGroup 2019-01-17T11:00:49Z DEBUG schema-compat-search-base: 2019-01-17T11:00:49Z DEBUG cn=groups, cn=accounts, dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-container-group: 2019-01-17T11:00:49Z DEBUG cn=compat, dc=local 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:00:49Z DEBUG objectclass=posixGroup 2019-01-17T11:00:49Z DEBUG gidNumber=%{gidNumber} 2019-01-17T11:00:49Z DEBUG memberUid=%{memberUid} 2019-01-17T11:00:49Z DEBUG memberUid=%deref_r("member","uid") 2019-01-17T11:00:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:00:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","") 2019-01-17T11:00:49Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2019-01-17T11:00:49Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:00:49Z DEBUG ipaexternalmember=%deref_r("member","ipaexternalmember") 2019-01-17T11:00:49Z DEBUG objectclass=ipaexternalgroup 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG groups 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG schema-compat-container-rdn: 2019-01-17T11:00:49Z DEBUG cn=groups 2019-01-17T11:00:49Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:00:49Z DEBUG dc=local 2019-01-17T11:00:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:00:49Z DEBUG cn=%{cn} 2019-01-17T11:00:49Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:00:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-search-filter: 2019-01-17T11:00:49Z DEBUG objectclass=posixGroup 2019-01-17T11:00:49Z DEBUG schema-compat-search-base: 2019-01-17T11:00:49Z DEBUG cn=groups, cn=accounts, dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-container-group: 2019-01-17T11:00:49Z DEBUG cn=compat, dc=local 2019-01-17T11:00:49Z DEBUG [] 2019-01-17T11:00:49Z DEBUG Updated 0 2019-01-17T11:00:49Z DEBUG Done 2019-01-17T11:00:49Z DEBUG Updating existing entry: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:00:49Z DEBUG objectclass=nisNetgroup 2019-01-17T11:00:49Z DEBUG memberNisNetgroup=%deref_r("member","cn") 2019-01-17T11:00:49Z DEBUG nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","%ifeq(\"hostCategory\",\"all\",\"\",\"-\")",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","%ifeq(\"userCategory\",\"all\",\"\",\"-\")"),%{nisDomainName:-}) 2019-01-17T11:00:49Z DEBUG schema-compat-check-access: 2019-01-17T11:00:49Z DEBUG yes 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG ng 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG schema-compat-container-rdn: 2019-01-17T11:00:49Z DEBUG cn=ng 2019-01-17T11:00:49Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:00:49Z DEBUG dc=local 2019-01-17T11:00:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-search-filter: 2019-01-17T11:00:49Z DEBUG (objectclass=ipaNisNetgroup) 2019-01-17T11:00:49Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:00:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:00:49Z DEBUG cn=%{cn} 2019-01-17T11:00:49Z DEBUG schema-compat-search-base: 2019-01-17T11:00:49Z DEBUG cn=ng, cn=alt, dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-container-group: 2019-01-17T11:00:49Z DEBUG cn=compat, dc=local 2019-01-17T11:00:49Z DEBUG add: 'top' to objectClass, current value [u'top', u'extensibleObject'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'extensibleObject', u'top'] 2019-01-17T11:00:49Z DEBUG add: 'extensibleObject' to objectClass, current value [u'extensibleObject', u'top'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'top', u'extensibleObject'] 2019-01-17T11:00:49Z DEBUG add: 'ng' to cn, current value [u'ng'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'ng'] 2019-01-17T11:00:49Z DEBUG add: 'cn=compat, dc=local' to schema-compat-container-group, current value [u'cn=compat, dc=local'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'cn=compat, dc=local'] 2019-01-17T11:00:49Z DEBUG add: 'cn=ng' to schema-compat-container-rdn, current value [u'cn=ng'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'cn=ng'] 2019-01-17T11:00:49Z DEBUG add: 'yes' to schema-compat-check-access, current value [u'yes'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'yes'] 2019-01-17T11:00:49Z DEBUG add: 'cn=ng, cn=alt, dc=local' to schema-compat-search-base, current value [u'cn=ng, cn=alt, dc=local'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'cn=ng, cn=alt, dc=local'] 2019-01-17T11:00:49Z DEBUG add: '(objectclass=ipaNisNetgroup)' to schema-compat-search-filter, current value [u'(objectclass=ipaNisNetgroup)'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'(objectclass=ipaNisNetgroup)'] 2019-01-17T11:00:49Z DEBUG add: 'cn=%{cn}' to schema-compat-entry-rdn, current value [u'cn=%{cn}'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'cn=%{cn}'] 2019-01-17T11:00:49Z DEBUG add: 'objectclass=nisNetgroup' to schema-compat-entry-attribute, current value [u'objectclass=nisNetgroup', u'memberNisNetgroup=%deref_r("member","cn")', u'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"-\\")",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"-\\")"),%{nisDomainName:-})'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'memberNisNetgroup=%deref_r("member","cn")', u'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"-\\")",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"-\\")"),%{nisDomainName:-})', u'objectclass=nisNetgroup'] 2019-01-17T11:00:49Z DEBUG add: 'memberNisNetgroup=%deref_r("member","cn")' to schema-compat-entry-attribute, current value [u'memberNisNetgroup=%deref_r("member","cn")', u'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"-\\")",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"-\\")"),%{nisDomainName:-})', u'objectclass=nisNetgroup'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"-\\")",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"-\\")"),%{nisDomainName:-})', u'objectclass=nisNetgroup', u'memberNisNetgroup=%deref_r("member","cn")'] 2019-01-17T11:00:49Z DEBUG add: 'nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","-",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","-"),%{nisDomainName:-})' to schema-compat-entry-attribute, current value [u'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"-\\")",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"-\\")"),%{nisDomainName:-})', u'objectclass=nisNetgroup', u'memberNisNetgroup=%deref_r("member","cn")'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"-\\")",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"-\\")"),%{nisDomainName:-})', u'objectclass=nisNetgroup', u'memberNisNetgroup=%deref_r("member","cn")', u'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","-",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","-"),%{nisDomainName:-})'] 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:00:49Z DEBUG nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","%ifeq(\"hostCategory\",\"all\",\"\",\"-\")",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","%ifeq(\"userCategory\",\"all\",\"\",\"-\")"),%{nisDomainName:-}) 2019-01-17T11:00:49Z DEBUG objectclass=nisNetgroup 2019-01-17T11:00:49Z DEBUG memberNisNetgroup=%deref_r("member","cn") 2019-01-17T11:00:49Z DEBUG nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","-",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","-"),%{nisDomainName:-}) 2019-01-17T11:00:49Z DEBUG schema-compat-check-access: 2019-01-17T11:00:49Z DEBUG yes 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG ng 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG schema-compat-container-rdn: 2019-01-17T11:00:49Z DEBUG cn=ng 2019-01-17T11:00:49Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:00:49Z DEBUG dc=local 2019-01-17T11:00:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-search-filter: 2019-01-17T11:00:49Z DEBUG (objectclass=ipaNisNetgroup) 2019-01-17T11:00:49Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:00:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:00:49Z DEBUG cn=%{cn} 2019-01-17T11:00:49Z DEBUG schema-compat-search-base: 2019-01-17T11:00:49Z DEBUG cn=ng, cn=alt, dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-container-group: 2019-01-17T11:00:49Z DEBUG cn=compat, dc=local 2019-01-17T11:00:49Z DEBUG [(0, u'schema-compat-entry-attribute', [u'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","-",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","-"),%{nisDomainName:-})'])] 2019-01-17T11:00:49Z DEBUG Updated 1 2019-01-17T11:00:49Z DEBUG Done 2019-01-17T11:00:49Z DEBUG Updating existing entry: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:00:49Z DEBUG objectclass=sudoRole 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2019-01-17T11:00:49Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2019-01-17T11:00:49Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2019-01-17T11:00:49Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2019-01-17T11:00:49Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2019-01-17T11:00:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2019-01-17T11:00:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2019-01-17T11:00:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2019-01-17T11:00:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2019-01-17T11:00:49Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoOption=%{ipaSudoOpt} 2019-01-17T11:00:49Z DEBUG sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn") 2019-01-17T11:00:49Z DEBUG sudoOrder=%{sudoOrder} 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG sudoers 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:00:49Z DEBUG dc=local 2019-01-17T11:00:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:00:49Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2019-01-17T11:00:49Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:00:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-search-filter: 2019-01-17T11:00:49Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2019-01-17T11:00:49Z DEBUG schema-compat-search-base: 2019-01-17T11:00:49Z DEBUG cn=sudorules, cn=sudo, dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-container-group: 2019-01-17T11:00:49Z DEBUG ou=SUDOers, dc=local 2019-01-17T11:00:49Z DEBUG add: 'top' to objectClass, current value [u'top', u'extensibleObject'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'extensibleObject', u'top'] 2019-01-17T11:00:49Z DEBUG add: 'extensibleObject' to objectClass, current value [u'extensibleObject', u'top'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'top', u'extensibleObject'] 2019-01-17T11:00:49Z DEBUG add: 'sudoers' to cn, current value [u'sudoers'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'sudoers'] 2019-01-17T11:00:49Z DEBUG add: 'ou=SUDOers, dc=local' to schema-compat-container-group, current value [u'ou=SUDOers, dc=local'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'ou=SUDOers, dc=local'] 2019-01-17T11:00:49Z DEBUG add: 'cn=sudorules, cn=sudo, dc=local' to schema-compat-search-base, current value [u'cn=sudorules, cn=sudo, dc=local'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'cn=sudorules, cn=sudo, dc=local'] 2019-01-17T11:00:49Z DEBUG add: '(&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE)))' to schema-compat-search-filter, current value [u'(&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE)))'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'(&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE)))'] 2019-01-17T11:00:49Z DEBUG add: '%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")' to schema-compat-entry-rdn, current value [u'%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")'] 2019-01-17T11:00:49Z DEBUG add: 'objectclass=sudoRole' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole'] 2019-01-17T11:00:49Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")' to schema-compat-entry-attribute, current value [u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")'] 2019-01-17T11:00:49Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")")' to schema-compat-entry-attribute, current value [u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2019-01-17T11:00:49Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")")' to schema-compat-entry-attribute, current value [u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")'] 2019-01-17T11:00:49Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")")' to schema-compat-entry-attribute, current value [u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2019-01-17T11:00:49Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")")' to schema-compat-entry-attribute, current value [u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")'] 2019-01-17T11:00:49Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")' to schema-compat-entry-attribute, current value [u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")'] 2019-01-17T11:00:49Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")")' to schema-compat-entry-attribute, current value [u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")'] 2019-01-17T11:00:49Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")")' to schema-compat-entry-attribute, current value [u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")'] 2019-01-17T11:00:49Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")")' to schema-compat-entry-attribute, current value [u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")'] 2019-01-17T11:00:49Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")")' to schema-compat-entry-attribute, current value [u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")'] 2019-01-17T11:00:49Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")' to schema-compat-entry-attribute, current value [u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2019-01-17T11:00:49Z DEBUG add: 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")")' to schema-compat-entry-attribute, current value [u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")'] 2019-01-17T11:00:49Z DEBUG add: 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")")' to schema-compat-entry-attribute, current value [u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")'] 2019-01-17T11:00:49Z DEBUG add: 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")' to schema-compat-entry-attribute, current value [u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")'] 2019-01-17T11:00:49Z DEBUG add: 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")' to schema-compat-entry-attribute, current value [u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")'] 2019-01-17T11:00:49Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")' to schema-compat-entry-attribute, current value [u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")'] 2019-01-17T11:00:49Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")' to schema-compat-entry-attribute, current value [u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")'] 2019-01-17T11:00:49Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")")' to schema-compat-entry-attribute, current value [u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2019-01-17T11:00:49Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")")' to schema-compat-entry-attribute, current value [u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2019-01-17T11:00:49Z DEBUG add: 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")' to schema-compat-entry-attribute, current value [u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")'] 2019-01-17T11:00:49Z DEBUG add: 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")")' to schema-compat-entry-attribute, current value [u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2019-01-17T11:00:49Z DEBUG add: 'sudoOption=%{ipaSudoOpt}' to schema-compat-entry-attribute, current value [u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}'] 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:00:49Z DEBUG sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn") 2019-01-17T11:00:49Z DEBUG sudoOrder=%{sudoOrder} 2019-01-17T11:00:49Z DEBUG objectclass=sudoRole 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2019-01-17T11:00:49Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2019-01-17T11:00:49Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2019-01-17T11:00:49Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2019-01-17T11:00:49Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2019-01-17T11:00:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2019-01-17T11:00:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2019-01-17T11:00:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2019-01-17T11:00:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2019-01-17T11:00:49Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoOption=%{ipaSudoOpt} 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG sudoers 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:00:49Z DEBUG dc=local 2019-01-17T11:00:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:00:49Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2019-01-17T11:00:49Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:00:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-search-filter: 2019-01-17T11:00:49Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2019-01-17T11:00:49Z DEBUG schema-compat-search-base: 2019-01-17T11:00:49Z DEBUG cn=sudorules, cn=sudo, dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-container-group: 2019-01-17T11:00:49Z DEBUG ou=SUDOers, dc=local 2019-01-17T11:00:49Z DEBUG [] 2019-01-17T11:00:49Z DEBUG Updated 0 2019-01-17T11:00:49Z DEBUG Done 2019-01-17T11:00:49Z DEBUG Updating existing entry: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:00:49Z DEBUG objectclass=device 2019-01-17T11:00:49Z DEBUG objectclass=ieee802Device 2019-01-17T11:00:49Z DEBUG cn=%{fqdn} 2019-01-17T11:00:49Z DEBUG macAddress=%{macAddress} 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG computers 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG schema-compat-container-rdn: 2019-01-17T11:00:49Z DEBUG cn=computers 2019-01-17T11:00:49Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:00:49Z DEBUG dc=local 2019-01-17T11:00:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:00:49Z DEBUG cn=%first("%{fqdn}") 2019-01-17T11:00:49Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:00:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-search-filter: 2019-01-17T11:00:49Z DEBUG (&(macAddress=*)(fqdn=*)(objectClass=ipaHost)) 2019-01-17T11:00:49Z DEBUG schema-compat-search-base: 2019-01-17T11:00:49Z DEBUG cn=computers, cn=accounts, dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-container-group: 2019-01-17T11:00:49Z DEBUG cn=compat, dc=local 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:00:49Z DEBUG objectclass=device 2019-01-17T11:00:49Z DEBUG objectclass=ieee802Device 2019-01-17T11:00:49Z DEBUG cn=%{fqdn} 2019-01-17T11:00:49Z DEBUG macAddress=%{macAddress} 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG computers 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG schema-compat-container-rdn: 2019-01-17T11:00:49Z DEBUG cn=computers 2019-01-17T11:00:49Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:00:49Z DEBUG dc=local 2019-01-17T11:00:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:00:49Z DEBUG cn=%first("%{fqdn}") 2019-01-17T11:00:49Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:00:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-search-filter: 2019-01-17T11:00:49Z DEBUG (&(macAddress=*)(fqdn=*)(objectClass=ipaHost)) 2019-01-17T11:00:49Z DEBUG schema-compat-search-base: 2019-01-17T11:00:49Z DEBUG cn=computers, cn=accounts, dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-container-group: 2019-01-17T11:00:49Z DEBUG cn=compat, dc=local 2019-01-17T11:00:49Z DEBUG [] 2019-01-17T11:00:49Z DEBUG Updated 0 2019-01-17T11:00:49Z DEBUG Done 2019-01-17T11:00:49Z DEBUG Updating existing entry: oid=2.16.840.1.113730.3.4.9,cn=features,cn=config 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: oid=2.16.840.1.113730.3.4.9,cn=features,cn=config 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG directoryServerFeature 2019-01-17T11:00:49Z DEBUG aci: 2019-01-17T11:00:49Z DEBUG (targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; ) 2019-01-17T11:00:49Z DEBUG oid: 2019-01-17T11:00:49Z DEBUG 2.16.840.1.113730.3.4.9 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG VLV Request Control 2019-01-17T11:00:49Z DEBUG only: set aci to '(targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; )', current value [u'(targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; )'] 2019-01-17T11:00:49Z DEBUG only: updated value [u'(targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; )'] 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: oid=2.16.840.1.113730.3.4.9,cn=features,cn=config 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG directoryServerFeature 2019-01-17T11:00:49Z DEBUG aci: 2019-01-17T11:00:49Z DEBUG (targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; ) 2019-01-17T11:00:49Z DEBUG oid: 2019-01-17T11:00:49Z DEBUG 2.16.840.1.113730.3.4.9 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG VLV Request Control 2019-01-17T11:00:49Z DEBUG [] 2019-01-17T11:00:49Z DEBUG Updated 0 2019-01-17T11:00:49Z DEBUG Done 2019-01-17T11:00:49Z DEBUG Updating existing entry: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:00:49Z DEBUG objectclass=sudoRole 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2019-01-17T11:00:49Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2019-01-17T11:00:49Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2019-01-17T11:00:49Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2019-01-17T11:00:49Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2019-01-17T11:00:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2019-01-17T11:00:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2019-01-17T11:00:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2019-01-17T11:00:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2019-01-17T11:00:49Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoOption=%{ipaSudoOpt} 2019-01-17T11:00:49Z DEBUG sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn") 2019-01-17T11:00:49Z DEBUG sudoOrder=%{sudoOrder} 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG sudoers 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:00:49Z DEBUG dc=local 2019-01-17T11:00:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:00:49Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2019-01-17T11:00:49Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:00:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-search-filter: 2019-01-17T11:00:49Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2019-01-17T11:00:49Z DEBUG schema-compat-search-base: 2019-01-17T11:00:49Z DEBUG cn=sudorules, cn=sudo, dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-container-group: 2019-01-17T11:00:49Z DEBUG ou=SUDOers, dc=local 2019-01-17T11:00:49Z DEBUG only: set schema-compat-entry-rdn to '%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")', current value [u'%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")'] 2019-01-17T11:00:49Z DEBUG only: updated value [u'%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")'] 2019-01-17T11:00:49Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2019-01-17T11:00:49Z DEBUG add: 'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}'] 2019-01-17T11:00:49Z DEBUG remove: 'sudoRunAsGroup=%deref("ipaSudoRunAs","cn")' from schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}'] 2019-01-17T11:00:49Z DEBUG remove: 'sudoRunAsGroup=%deref("ipaSudoRunAs","cn")' not in schema-compat-entry-attribute 2019-01-17T11:00:49Z DEBUG remove: 'sudoRunAsUser=%{ipaSudoRunAsExtUser}' from schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}'] 2019-01-17T11:00:49Z DEBUG remove: 'sudoRunAsUser=%{ipaSudoRunAsExtUser}' not in schema-compat-entry-attribute 2019-01-17T11:00:49Z DEBUG remove: 'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}' from schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}'] 2019-01-17T11:00:49Z DEBUG remove: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2019-01-17T11:00:49Z DEBUG remove: 'sudoRunAsUser=%deref("ipaSudoRunAs","uid")' from schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2019-01-17T11:00:49Z DEBUG remove: 'sudoRunAsUser=%deref("ipaSudoRunAs","uid")' not in schema-compat-entry-attribute 2019-01-17T11:00:49Z DEBUG remove: 'sudoRunAsGroup=%{ipaSudoRunAsExtGroup}' from schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2019-01-17T11:00:49Z DEBUG remove: 'sudoRunAsGroup=%{ipaSudoRunAsExtGroup}' not in schema-compat-entry-attribute 2019-01-17T11:00:49Z DEBUG remove: 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")' from schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2019-01-17T11:00:49Z DEBUG remove: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:00:49Z DEBUG objectclass=sudoRole 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2019-01-17T11:00:49Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2019-01-17T11:00:49Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2019-01-17T11:00:49Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2019-01-17T11:00:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2019-01-17T11:00:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2019-01-17T11:00:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2019-01-17T11:00:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2019-01-17T11:00:49Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoOption=%{ipaSudoOpt} 2019-01-17T11:00:49Z DEBUG sudoOrder=%{sudoOrder} 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG sudoers 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:00:49Z DEBUG dc=local 2019-01-17T11:00:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:00:49Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2019-01-17T11:00:49Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:00:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-search-filter: 2019-01-17T11:00:49Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2019-01-17T11:00:49Z DEBUG schema-compat-search-base: 2019-01-17T11:00:49Z DEBUG cn=sudorules, cn=sudo, dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-container-group: 2019-01-17T11:00:49Z DEBUG ou=SUDOers, dc=local 2019-01-17T11:00:49Z DEBUG [(1, u'schema-compat-entry-attribute', [u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")'])] 2019-01-17T11:00:49Z DEBUG Updated 1 2019-01-17T11:00:49Z DEBUG Done 2019-01-17T11:00:49Z DEBUG Updating existing entry: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:00:49Z DEBUG objectclass=sudoRole 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2019-01-17T11:00:49Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2019-01-17T11:00:49Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2019-01-17T11:00:49Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2019-01-17T11:00:49Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2019-01-17T11:00:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2019-01-17T11:00:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2019-01-17T11:00:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2019-01-17T11:00:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2019-01-17T11:00:49Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoOption=%{ipaSudoOpt} 2019-01-17T11:00:49Z DEBUG sudoOrder=%{sudoOrder} 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG sudoers 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:00:49Z DEBUG dc=local 2019-01-17T11:00:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:00:49Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2019-01-17T11:00:49Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:00:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-search-filter: 2019-01-17T11:00:49Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2019-01-17T11:00:49Z DEBUG schema-compat-search-base: 2019-01-17T11:00:49Z DEBUG cn=sudorules, cn=sudo, dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-container-group: 2019-01-17T11:00:49Z DEBUG ou=SUDOers, dc=local 2019-01-17T11:00:49Z DEBUG add: 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")'] 2019-01-17T11:00:49Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")'] 2019-01-17T11:00:49Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")'] 2019-01-17T11:00:49Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2019-01-17T11:00:49Z DEBUG add: 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")'] 2019-01-17T11:00:49Z DEBUG add: 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2019-01-17T11:00:49Z DEBUG remove: 'cn=changelog' from schema-compat-ignore-subtree, current value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:00:49Z DEBUG remove: 'cn=changelog' not in schema-compat-ignore-subtree 2019-01-17T11:00:49Z DEBUG remove: 'o=ipaca' from schema-compat-ignore-subtree, current value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:00:49Z DEBUG remove: 'o=ipaca' not in schema-compat-ignore-subtree 2019-01-17T11:00:49Z DEBUG add: 'dc=local' to schema-compat-restrict-subtree, current value [u'dc=local', u'cn=Schema Compatibility,cn=plugins,cn=config'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'cn=Schema Compatibility,cn=plugins,cn=config', u'dc=local'] 2019-01-17T11:00:49Z DEBUG add: 'cn=Schema Compatibility,cn=plugins,cn=config' to schema-compat-restrict-subtree, current value [u'cn=Schema Compatibility,cn=plugins,cn=config', u'dc=local'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'dc=local', u'cn=Schema Compatibility,cn=plugins,cn=config'] 2019-01-17T11:00:49Z DEBUG add: 'cn=dna,cn=ipa,cn=etc,dc=local' to schema-compat-ignore-subtree, current value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'cn=topology,cn=ipa,cn=etc,dc=local', u'cn=dna,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:00:49Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=local' to schema-compat-ignore-subtree, current value [u'cn=topology,cn=ipa,cn=etc,dc=local', u'cn=dna,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:00:49Z DEBUG objectclass=sudoRole 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2019-01-17T11:00:49Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2019-01-17T11:00:49Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2019-01-17T11:00:49Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2019-01-17T11:00:49Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2019-01-17T11:00:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoOption=%{ipaSudoOpt} 2019-01-17T11:00:49Z DEBUG sudoOrder=%{sudoOrder} 2019-01-17T11:00:49Z DEBUG sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn") 2019-01-17T11:00:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2019-01-17T11:00:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2019-01-17T11:00:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2019-01-17T11:00:49Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2019-01-17T11:00:49Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG sudoers 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:00:49Z DEBUG dc=local 2019-01-17T11:00:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:00:49Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2019-01-17T11:00:49Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:00:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-search-filter: 2019-01-17T11:00:49Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2019-01-17T11:00:49Z DEBUG schema-compat-search-base: 2019-01-17T11:00:49Z DEBUG cn=sudorules, cn=sudo, dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-container-group: 2019-01-17T11:00:49Z DEBUG ou=SUDOers, dc=local 2019-01-17T11:00:49Z DEBUG [(0, u'schema-compat-entry-attribute', [u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")'])] 2019-01-17T11:00:49Z DEBUG Updated 1 2019-01-17T11:00:49Z DEBUG Done 2019-01-17T11:00:49Z DEBUG Updating existing entry: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:00:49Z DEBUG objectclass=nisNetgroup 2019-01-17T11:00:49Z DEBUG memberNisNetgroup=%deref_r("member","cn") 2019-01-17T11:00:49Z DEBUG nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","%ifeq(\"hostCategory\",\"all\",\"\",\"-\")",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","%ifeq(\"userCategory\",\"all\",\"\",\"-\")"),%{nisDomainName:-}) 2019-01-17T11:00:49Z DEBUG nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","-",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","-"),%{nisDomainName:-}) 2019-01-17T11:00:49Z DEBUG schema-compat-check-access: 2019-01-17T11:00:49Z DEBUG yes 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG ng 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG schema-compat-container-rdn: 2019-01-17T11:00:49Z DEBUG cn=ng 2019-01-17T11:00:49Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:00:49Z DEBUG dc=local 2019-01-17T11:00:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-search-filter: 2019-01-17T11:00:49Z DEBUG (objectclass=ipaNisNetgroup) 2019-01-17T11:00:49Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:00:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:00:49Z DEBUG cn=%{cn} 2019-01-17T11:00:49Z DEBUG schema-compat-search-base: 2019-01-17T11:00:49Z DEBUG cn=ng, cn=alt, dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-container-group: 2019-01-17T11:00:49Z DEBUG cn=compat, dc=local 2019-01-17T11:00:49Z DEBUG replace: updated value [u'objectclass=nisNetgroup', u'memberNisNetgroup=%deref_r("member","cn")', u'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"-\\")",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"-\\")"),%{nisDomainName:-})', u'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"-\\")",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"-\\")"),%{nisDomainName:-})'] 2019-01-17T11:00:49Z DEBUG remove: 'cn=changelog' from schema-compat-ignore-subtree, current value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:00:49Z DEBUG remove: 'cn=changelog' not in schema-compat-ignore-subtree 2019-01-17T11:00:49Z DEBUG remove: 'o=ipaca' from schema-compat-ignore-subtree, current value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:00:49Z DEBUG remove: 'o=ipaca' not in schema-compat-ignore-subtree 2019-01-17T11:00:49Z DEBUG add: 'dc=local' to schema-compat-restrict-subtree, current value [u'dc=local', u'cn=Schema Compatibility,cn=plugins,cn=config'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'cn=Schema Compatibility,cn=plugins,cn=config', u'dc=local'] 2019-01-17T11:00:49Z DEBUG add: 'cn=Schema Compatibility,cn=plugins,cn=config' to schema-compat-restrict-subtree, current value [u'cn=Schema Compatibility,cn=plugins,cn=config', u'dc=local'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'dc=local', u'cn=Schema Compatibility,cn=plugins,cn=config'] 2019-01-17T11:00:49Z DEBUG add: 'cn=dna,cn=ipa,cn=etc,dc=local' to schema-compat-ignore-subtree, current value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'cn=topology,cn=ipa,cn=etc,dc=local', u'cn=dna,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:00:49Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=local' to schema-compat-ignore-subtree, current value [u'cn=topology,cn=ipa,cn=etc,dc=local', u'cn=dna,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:00:49Z DEBUG objectclass=nisNetgroup 2019-01-17T11:00:49Z DEBUG memberNisNetgroup=%deref_r("member","cn") 2019-01-17T11:00:49Z DEBUG nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","%ifeq(\"hostCategory\",\"all\",\"\",\"-\")",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","%ifeq(\"userCategory\",\"all\",\"\",\"-\")"),%{nisDomainName:-}) 2019-01-17T11:00:49Z DEBUG nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","%ifeq(\"hostCategory\",\"all\",\"\",\"-\")",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","%ifeq(\"userCategory\",\"all\",\"\",\"-\")"),%{nisDomainName:-}) 2019-01-17T11:00:49Z DEBUG schema-compat-check-access: 2019-01-17T11:00:49Z DEBUG yes 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG ng 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG schema-compat-container-rdn: 2019-01-17T11:00:49Z DEBUG cn=ng 2019-01-17T11:00:49Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:00:49Z DEBUG dc=local 2019-01-17T11:00:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-search-filter: 2019-01-17T11:00:49Z DEBUG (objectclass=ipaNisNetgroup) 2019-01-17T11:00:49Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:00:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:00:49Z DEBUG cn=%{cn} 2019-01-17T11:00:49Z DEBUG schema-compat-search-base: 2019-01-17T11:00:49Z DEBUG cn=ng, cn=alt, dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-container-group: 2019-01-17T11:00:49Z DEBUG cn=compat, dc=local 2019-01-17T11:00:49Z DEBUG [(1, u'schema-compat-entry-attribute', [u'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","-",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","-"),%{nisDomainName:-})'])] 2019-01-17T11:00:49Z DEBUG Updated 1 2019-01-17T11:00:49Z DEBUG Done 2019-01-17T11:00:49Z DEBUG Updating existing entry: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:00:49Z DEBUG objectclass=device 2019-01-17T11:00:49Z DEBUG objectclass=ieee802Device 2019-01-17T11:00:49Z DEBUG cn=%{fqdn} 2019-01-17T11:00:49Z DEBUG macAddress=%{macAddress} 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG computers 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG schema-compat-container-rdn: 2019-01-17T11:00:49Z DEBUG cn=computers 2019-01-17T11:00:49Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:00:49Z DEBUG dc=local 2019-01-17T11:00:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:00:49Z DEBUG cn=%first("%{fqdn}") 2019-01-17T11:00:49Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:00:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-search-filter: 2019-01-17T11:00:49Z DEBUG (&(macAddress=*)(fqdn=*)(objectClass=ipaHost)) 2019-01-17T11:00:49Z DEBUG schema-compat-search-base: 2019-01-17T11:00:49Z DEBUG cn=computers, cn=accounts, dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-container-group: 2019-01-17T11:00:49Z DEBUG cn=compat, dc=local 2019-01-17T11:00:49Z DEBUG remove: 'cn=changelog' from schema-compat-ignore-subtree, current value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:00:49Z DEBUG remove: 'cn=changelog' not in schema-compat-ignore-subtree 2019-01-17T11:00:49Z DEBUG remove: 'o=ipaca' from schema-compat-ignore-subtree, current value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:00:49Z DEBUG remove: 'o=ipaca' not in schema-compat-ignore-subtree 2019-01-17T11:00:49Z DEBUG add: 'dc=local' to schema-compat-restrict-subtree, current value [u'dc=local', u'cn=Schema Compatibility,cn=plugins,cn=config'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'cn=Schema Compatibility,cn=plugins,cn=config', u'dc=local'] 2019-01-17T11:00:49Z DEBUG add: 'cn=Schema Compatibility,cn=plugins,cn=config' to schema-compat-restrict-subtree, current value [u'cn=Schema Compatibility,cn=plugins,cn=config', u'dc=local'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'dc=local', u'cn=Schema Compatibility,cn=plugins,cn=config'] 2019-01-17T11:00:49Z DEBUG add: 'cn=dna,cn=ipa,cn=etc,dc=local' to schema-compat-ignore-subtree, current value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'cn=topology,cn=ipa,cn=etc,dc=local', u'cn=dna,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:00:49Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=local' to schema-compat-ignore-subtree, current value [u'cn=topology,cn=ipa,cn=etc,dc=local', u'cn=dna,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:00:49Z DEBUG objectclass=device 2019-01-17T11:00:49Z DEBUG objectclass=ieee802Device 2019-01-17T11:00:49Z DEBUG cn=%{fqdn} 2019-01-17T11:00:49Z DEBUG macAddress=%{macAddress} 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG computers 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG schema-compat-container-rdn: 2019-01-17T11:00:49Z DEBUG cn=computers 2019-01-17T11:00:49Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:00:49Z DEBUG dc=local 2019-01-17T11:00:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:00:49Z DEBUG cn=%first("%{fqdn}") 2019-01-17T11:00:49Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:00:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-search-filter: 2019-01-17T11:00:49Z DEBUG (&(macAddress=*)(fqdn=*)(objectClass=ipaHost)) 2019-01-17T11:00:49Z DEBUG schema-compat-search-base: 2019-01-17T11:00:49Z DEBUG cn=computers, cn=accounts, dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-container-group: 2019-01-17T11:00:49Z DEBUG cn=compat, dc=local 2019-01-17T11:00:49Z DEBUG [] 2019-01-17T11:00:49Z DEBUG Updated 0 2019-01-17T11:00:49Z DEBUG Done 2019-01-17T11:00:49Z DEBUG Updating existing entry: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:00:49Z DEBUG objectclass=sudoRole 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2019-01-17T11:00:49Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2019-01-17T11:00:49Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2019-01-17T11:00:49Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2019-01-17T11:00:49Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2019-01-17T11:00:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2019-01-17T11:00:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2019-01-17T11:00:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2019-01-17T11:00:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2019-01-17T11:00:49Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoOption=%{ipaSudoOpt} 2019-01-17T11:00:49Z DEBUG sudoOrder=%{sudoOrder} 2019-01-17T11:00:49Z DEBUG sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn") 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG sudoers 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:00:49Z DEBUG dc=local 2019-01-17T11:00:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:00:49Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2019-01-17T11:00:49Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:00:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-search-filter: 2019-01-17T11:00:49Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2019-01-17T11:00:49Z DEBUG schema-compat-search-base: 2019-01-17T11:00:49Z DEBUG cn=sudorules, cn=sudo, dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-container-group: 2019-01-17T11:00:49Z DEBUG ou=SUDOers, dc=local 2019-01-17T11:00:49Z DEBUG add: 'sudoOrder=%{sudoOrder}' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}'] 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:00:49Z DEBUG objectclass=sudoRole 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2019-01-17T11:00:49Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2019-01-17T11:00:49Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2019-01-17T11:00:49Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2019-01-17T11:00:49Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2019-01-17T11:00:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2019-01-17T11:00:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2019-01-17T11:00:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2019-01-17T11:00:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2019-01-17T11:00:49Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:00:49Z DEBUG sudoOption=%{ipaSudoOpt} 2019-01-17T11:00:49Z DEBUG sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn") 2019-01-17T11:00:49Z DEBUG sudoOrder=%{sudoOrder} 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG sudoers 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:00:49Z DEBUG dc=local 2019-01-17T11:00:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:00:49Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2019-01-17T11:00:49Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:00:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-search-filter: 2019-01-17T11:00:49Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2019-01-17T11:00:49Z DEBUG schema-compat-search-base: 2019-01-17T11:00:49Z DEBUG cn=sudorules, cn=sudo, dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-container-group: 2019-01-17T11:00:49Z DEBUG ou=SUDOers, dc=local 2019-01-17T11:00:49Z DEBUG [] 2019-01-17T11:00:49Z DEBUG Updated 0 2019-01-17T11:00:49Z DEBUG Done 2019-01-17T11:00:49Z DEBUG Updating existing entry: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:00:49Z DEBUG objectclass=posixAccount 2019-01-17T11:00:49Z DEBUG gecos=%{cn} 2019-01-17T11:00:49Z DEBUG cn=%{cn} 2019-01-17T11:00:49Z DEBUG uidNumber=%{uidNumber} 2019-01-17T11:00:49Z DEBUG gidNumber=%{gidNumber} 2019-01-17T11:00:49Z DEBUG loginShell=%{loginShell} 2019-01-17T11:00:49Z DEBUG homeDirectory=%{homeDirectory} 2019-01-17T11:00:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:00:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","") 2019-01-17T11:00:49Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2019-01-17T11:00:49Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:00:49Z DEBUG uid=%{uid} 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG users 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG schema-compat-container-rdn: 2019-01-17T11:00:49Z DEBUG cn=users 2019-01-17T11:00:49Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:00:49Z DEBUG dc=local 2019-01-17T11:00:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:00:49Z DEBUG uid=%first("%{uid}") 2019-01-17T11:00:49Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:00:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-search-filter: 2019-01-17T11:00:49Z DEBUG objectclass=posixAccount 2019-01-17T11:00:49Z DEBUG schema-compat-search-base: 2019-01-17T11:00:49Z DEBUG cn=users, cn=accounts, dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-container-group: 2019-01-17T11:00:49Z DEBUG cn=compat, dc=local 2019-01-17T11:00:49Z DEBUG remove: 'cn=changelog' from schema-compat-ignore-subtree, current value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:00:49Z DEBUG remove: 'cn=changelog' not in schema-compat-ignore-subtree 2019-01-17T11:00:49Z DEBUG remove: 'o=ipaca' from schema-compat-ignore-subtree, current value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:00:49Z DEBUG remove: 'o=ipaca' not in schema-compat-ignore-subtree 2019-01-17T11:00:49Z DEBUG add: 'dc=local' to schema-compat-restrict-subtree, current value [u'dc=local', u'cn=Schema Compatibility,cn=plugins,cn=config'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'cn=Schema Compatibility,cn=plugins,cn=config', u'dc=local'] 2019-01-17T11:00:49Z DEBUG add: 'cn=Schema Compatibility,cn=plugins,cn=config' to schema-compat-restrict-subtree, current value [u'cn=Schema Compatibility,cn=plugins,cn=config', u'dc=local'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'dc=local', u'cn=Schema Compatibility,cn=plugins,cn=config'] 2019-01-17T11:00:49Z DEBUG add: 'cn=dna,cn=ipa,cn=etc,dc=local' to schema-compat-ignore-subtree, current value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'cn=topology,cn=ipa,cn=etc,dc=local', u'cn=dna,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:00:49Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=local' to schema-compat-ignore-subtree, current value [u'cn=topology,cn=ipa,cn=etc,dc=local', u'cn=dna,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:00:49Z DEBUG objectclass=posixAccount 2019-01-17T11:00:49Z DEBUG gecos=%{cn} 2019-01-17T11:00:49Z DEBUG cn=%{cn} 2019-01-17T11:00:49Z DEBUG uidNumber=%{uidNumber} 2019-01-17T11:00:49Z DEBUG gidNumber=%{gidNumber} 2019-01-17T11:00:49Z DEBUG loginShell=%{loginShell} 2019-01-17T11:00:49Z DEBUG homeDirectory=%{homeDirectory} 2019-01-17T11:00:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:00:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","") 2019-01-17T11:00:49Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2019-01-17T11:00:49Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:00:49Z DEBUG uid=%{uid} 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG users 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG schema-compat-container-rdn: 2019-01-17T11:00:49Z DEBUG cn=users 2019-01-17T11:00:49Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:00:49Z DEBUG dc=local 2019-01-17T11:00:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:00:49Z DEBUG uid=%first("%{uid}") 2019-01-17T11:00:49Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:00:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-search-filter: 2019-01-17T11:00:49Z DEBUG objectclass=posixAccount 2019-01-17T11:00:49Z DEBUG schema-compat-search-base: 2019-01-17T11:00:49Z DEBUG cn=users, cn=accounts, dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-container-group: 2019-01-17T11:00:49Z DEBUG cn=compat, dc=local 2019-01-17T11:00:49Z DEBUG [] 2019-01-17T11:00:49Z DEBUG Updated 0 2019-01-17T11:00:49Z DEBUG Done 2019-01-17T11:00:49Z DEBUG Updating existing entry: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:00:49Z DEBUG objectclass=posixGroup 2019-01-17T11:00:49Z DEBUG gidNumber=%{gidNumber} 2019-01-17T11:00:49Z DEBUG memberUid=%{memberUid} 2019-01-17T11:00:49Z DEBUG memberUid=%deref_r("member","uid") 2019-01-17T11:00:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:00:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","") 2019-01-17T11:00:49Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2019-01-17T11:00:49Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:00:49Z DEBUG ipaexternalmember=%deref_r("member","ipaexternalmember") 2019-01-17T11:00:49Z DEBUG objectclass=ipaexternalgroup 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG groups 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG schema-compat-container-rdn: 2019-01-17T11:00:49Z DEBUG cn=groups 2019-01-17T11:00:49Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:00:49Z DEBUG dc=local 2019-01-17T11:00:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:00:49Z DEBUG cn=%{cn} 2019-01-17T11:00:49Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:00:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-search-filter: 2019-01-17T11:00:49Z DEBUG objectclass=posixGroup 2019-01-17T11:00:49Z DEBUG schema-compat-search-base: 2019-01-17T11:00:49Z DEBUG cn=groups, cn=accounts, dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-container-group: 2019-01-17T11:00:49Z DEBUG cn=compat, dc=local 2019-01-17T11:00:49Z DEBUG remove: 'cn=changelog' from schema-compat-ignore-subtree, current value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:00:49Z DEBUG remove: 'cn=changelog' not in schema-compat-ignore-subtree 2019-01-17T11:00:49Z DEBUG remove: 'o=ipaca' from schema-compat-ignore-subtree, current value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:00:49Z DEBUG remove: 'o=ipaca' not in schema-compat-ignore-subtree 2019-01-17T11:00:49Z DEBUG add: 'dc=local' to schema-compat-restrict-subtree, current value [u'dc=local', u'cn=Schema Compatibility,cn=plugins,cn=config'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'cn=Schema Compatibility,cn=plugins,cn=config', u'dc=local'] 2019-01-17T11:00:49Z DEBUG add: 'cn=Schema Compatibility,cn=plugins,cn=config' to schema-compat-restrict-subtree, current value [u'cn=Schema Compatibility,cn=plugins,cn=config', u'dc=local'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'dc=local', u'cn=Schema Compatibility,cn=plugins,cn=config'] 2019-01-17T11:00:49Z DEBUG add: 'cn=dna,cn=ipa,cn=etc,dc=local' to schema-compat-ignore-subtree, current value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'cn=topology,cn=ipa,cn=etc,dc=local', u'cn=dna,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:00:49Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=local' to schema-compat-ignore-subtree, current value [u'cn=topology,cn=ipa,cn=etc,dc=local', u'cn=dna,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:00:49Z DEBUG objectclass=posixGroup 2019-01-17T11:00:49Z DEBUG gidNumber=%{gidNumber} 2019-01-17T11:00:49Z DEBUG memberUid=%{memberUid} 2019-01-17T11:00:49Z DEBUG memberUid=%deref_r("member","uid") 2019-01-17T11:00:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:00:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","") 2019-01-17T11:00:49Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2019-01-17T11:00:49Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:00:49Z DEBUG ipaexternalmember=%deref_r("member","ipaexternalmember") 2019-01-17T11:00:49Z DEBUG objectclass=ipaexternalgroup 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG groups 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG schema-compat-container-rdn: 2019-01-17T11:00:49Z DEBUG cn=groups 2019-01-17T11:00:49Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:00:49Z DEBUG dc=local 2019-01-17T11:00:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:00:49Z DEBUG cn=%{cn} 2019-01-17T11:00:49Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:00:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-search-filter: 2019-01-17T11:00:49Z DEBUG objectclass=posixGroup 2019-01-17T11:00:49Z DEBUG schema-compat-search-base: 2019-01-17T11:00:49Z DEBUG cn=groups, cn=accounts, dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-container-group: 2019-01-17T11:00:49Z DEBUG cn=compat, dc=local 2019-01-17T11:00:49Z DEBUG [] 2019-01-17T11:00:49Z DEBUG Updated 0 2019-01-17T11:00:49Z DEBUG Done 2019-01-17T11:00:49Z DEBUG Updating existing entry: cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:00:49Z DEBUG on 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG Schema Compatibility 2019-01-17T11:00:49Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:49Z DEBUG none 2019-01-17T11:00:49Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:49Z DEBUG none 2019-01-17T11:00:49Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:49Z DEBUG off 2019-01-17T11:00:49Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:49Z DEBUG /usr/lib64/dirsrv/plugins/schemacompat-plugin.so 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG nsSlapdPlugin 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:49Z DEBUG none 2019-01-17T11:00:49Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:49Z DEBUG schema_compat_plugin_init 2019-01-17T11:00:49Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:00:49Z DEBUG 40 2019-01-17T11:00:49Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:49Z DEBUG object 2019-01-17T11:00:49Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:49Z DEBUG none 2019-01-17T11:00:49Z DEBUG add: '40' to nsslapd-pluginprecedence, current value [u'40'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'40'] 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:00:49Z DEBUG on 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG Schema Compatibility 2019-01-17T11:00:49Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:00:49Z DEBUG none 2019-01-17T11:00:49Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:00:49Z DEBUG none 2019-01-17T11:00:49Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:00:49Z DEBUG off 2019-01-17T11:00:49Z DEBUG nsslapd-pluginPath: 2019-01-17T11:00:49Z DEBUG /usr/lib64/dirsrv/plugins/schemacompat-plugin.so 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG nsSlapdPlugin 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG nsslapd-pluginId: 2019-01-17T11:00:49Z DEBUG none 2019-01-17T11:00:49Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:00:49Z DEBUG schema_compat_plugin_init 2019-01-17T11:00:49Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:00:49Z DEBUG 40 2019-01-17T11:00:49Z DEBUG nsslapd-pluginType: 2019-01-17T11:00:49Z DEBUG object 2019-01-17T11:00:49Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:00:49Z DEBUG none 2019-01-17T11:00:49Z DEBUG [] 2019-01-17T11:00:49Z DEBUG Updated 0 2019-01-17T11:00:49Z DEBUG Done 2019-01-17T11:00:49Z DEBUG Updating existing entry: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:00:49Z DEBUG objectclass=posixAccount 2019-01-17T11:00:49Z DEBUG gecos=%{cn} 2019-01-17T11:00:49Z DEBUG cn=%{cn} 2019-01-17T11:00:49Z DEBUG uidNumber=%{uidNumber} 2019-01-17T11:00:49Z DEBUG gidNumber=%{gidNumber} 2019-01-17T11:00:49Z DEBUG loginShell=%{loginShell} 2019-01-17T11:00:49Z DEBUG homeDirectory=%{homeDirectory} 2019-01-17T11:00:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:00:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","") 2019-01-17T11:00:49Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2019-01-17T11:00:49Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:00:49Z DEBUG uid=%{uid} 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG users 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG schema-compat-container-rdn: 2019-01-17T11:00:49Z DEBUG cn=users 2019-01-17T11:00:49Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:00:49Z DEBUG dc=local 2019-01-17T11:00:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:00:49Z DEBUG uid=%first("%{uid}") 2019-01-17T11:00:49Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:00:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-search-filter: 2019-01-17T11:00:49Z DEBUG objectclass=posixAccount 2019-01-17T11:00:49Z DEBUG schema-compat-search-base: 2019-01-17T11:00:49Z DEBUG cn=users, cn=accounts, dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-container-group: 2019-01-17T11:00:49Z DEBUG cn=compat, dc=local 2019-01-17T11:00:49Z DEBUG add: '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")' to schema-compat-entry-attribute, current value [u'objectclass=posixAccount', u'gecos=%{cn}', u'cn=%{cn}', u'uidNumber=%{uidNumber}', u'gidNumber=%{gidNumber}', u'loginShell=%{loginShell}', u'homeDirectory=%{homeDirectory}', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'uid=%{uid}'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'objectclass=posixAccount', u'gecos=%{cn}', u'cn=%{cn}', u'uidNumber=%{uidNumber}', u'gidNumber=%{gidNumber}', u'loginShell=%{loginShell}', u'homeDirectory=%{homeDirectory}', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'uid=%{uid}', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")'] 2019-01-17T11:00:49Z DEBUG add: '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")' to schema-compat-entry-attribute, current value [u'objectclass=posixAccount', u'gecos=%{cn}', u'cn=%{cn}', u'uidNumber=%{uidNumber}', u'gidNumber=%{gidNumber}', u'loginShell=%{loginShell}', u'homeDirectory=%{homeDirectory}', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'uid=%{uid}', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'objectclass=posixAccount', u'gecos=%{cn}', u'cn=%{cn}', u'uidNumber=%{uidNumber}', u'gidNumber=%{gidNumber}', u'loginShell=%{loginShell}', u'homeDirectory=%{homeDirectory}', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'uid=%{uid}', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")'] 2019-01-17T11:00:49Z DEBUG add: 'ipaanchoruuid=%{ipaanchoruuid}' to schema-compat-entry-attribute, current value [u'objectclass=posixAccount', u'gecos=%{cn}', u'cn=%{cn}', u'uidNumber=%{uidNumber}', u'gidNumber=%{gidNumber}', u'loginShell=%{loginShell}', u'homeDirectory=%{homeDirectory}', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'uid=%{uid}', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'objectclass=posixAccount', u'gecos=%{cn}', u'cn=%{cn}', u'uidNumber=%{uidNumber}', u'gidNumber=%{gidNumber}', u'loginShell=%{loginShell}', u'homeDirectory=%{homeDirectory}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'uid=%{uid}', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}'] 2019-01-17T11:00:49Z DEBUG add: '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")' to schema-compat-entry-attribute, current value [u'objectclass=posixAccount', u'gecos=%{cn}', u'cn=%{cn}', u'uidNumber=%{uidNumber}', u'gidNumber=%{gidNumber}', u'loginShell=%{loginShell}', u'homeDirectory=%{homeDirectory}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'uid=%{uid}', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'objectclass=posixAccount', u'gecos=%{cn}', u'cn=%{cn}', u'uidNumber=%{uidNumber}', u'gidNumber=%{gidNumber}', u'loginShell=%{loginShell}', u'homeDirectory=%{homeDirectory}', u'uid=%{uid}', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")'] 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:00:49Z DEBUG objectclass=posixAccount 2019-01-17T11:00:49Z DEBUG gecos=%{cn} 2019-01-17T11:00:49Z DEBUG cn=%{cn} 2019-01-17T11:00:49Z DEBUG uidNumber=%{uidNumber} 2019-01-17T11:00:49Z DEBUG gidNumber=%{gidNumber} 2019-01-17T11:00:49Z DEBUG loginShell=%{loginShell} 2019-01-17T11:00:49Z DEBUG homeDirectory=%{homeDirectory} 2019-01-17T11:00:49Z DEBUG uid=%{uid} 2019-01-17T11:00:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:00:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","") 2019-01-17T11:00:49Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2019-01-17T11:00:49Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG users 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG schema-compat-container-rdn: 2019-01-17T11:00:49Z DEBUG cn=users 2019-01-17T11:00:49Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:00:49Z DEBUG dc=local 2019-01-17T11:00:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:00:49Z DEBUG uid=%first("%{uid}") 2019-01-17T11:00:49Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:00:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-search-filter: 2019-01-17T11:00:49Z DEBUG objectclass=posixAccount 2019-01-17T11:00:49Z DEBUG schema-compat-search-base: 2019-01-17T11:00:49Z DEBUG cn=users, cn=accounts, dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-container-group: 2019-01-17T11:00:49Z DEBUG cn=compat, dc=local 2019-01-17T11:00:49Z DEBUG [] 2019-01-17T11:00:49Z DEBUG Updated 0 2019-01-17T11:00:49Z DEBUG Done 2019-01-17T11:00:49Z DEBUG Updating existing entry: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:00:49Z DEBUG objectclass=posixGroup 2019-01-17T11:00:49Z DEBUG gidNumber=%{gidNumber} 2019-01-17T11:00:49Z DEBUG memberUid=%{memberUid} 2019-01-17T11:00:49Z DEBUG memberUid=%deref_r("member","uid") 2019-01-17T11:00:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:00:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","") 2019-01-17T11:00:49Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2019-01-17T11:00:49Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:00:49Z DEBUG ipaexternalmember=%deref_r("member","ipaexternalmember") 2019-01-17T11:00:49Z DEBUG objectclass=ipaexternalgroup 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG groups 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG schema-compat-container-rdn: 2019-01-17T11:00:49Z DEBUG cn=groups 2019-01-17T11:00:49Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:00:49Z DEBUG dc=local 2019-01-17T11:00:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:00:49Z DEBUG cn=%{cn} 2019-01-17T11:00:49Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:00:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-search-filter: 2019-01-17T11:00:49Z DEBUG objectclass=posixGroup 2019-01-17T11:00:49Z DEBUG schema-compat-search-base: 2019-01-17T11:00:49Z DEBUG cn=groups, cn=accounts, dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-container-group: 2019-01-17T11:00:49Z DEBUG cn=compat, dc=local 2019-01-17T11:00:49Z DEBUG add: '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")' to schema-compat-entry-attribute, current value [u'objectclass=posixGroup', u'gidNumber=%{gidNumber}', u'memberUid=%{memberUid}', u'memberUid=%deref_r("member","uid")', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'ipaexternalmember=%deref_r("member","ipaexternalmember")', u'objectclass=ipaexternalgroup'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'objectclass=posixGroup', u'gidNumber=%{gidNumber}', u'memberUid=%{memberUid}', u'memberUid=%deref_r("member","uid")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'ipaexternalmember=%deref_r("member","ipaexternalmember")', u'objectclass=ipaexternalgroup', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")'] 2019-01-17T11:00:49Z DEBUG add: '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")' to schema-compat-entry-attribute, current value [u'objectclass=posixGroup', u'gidNumber=%{gidNumber}', u'memberUid=%{memberUid}', u'memberUid=%deref_r("member","uid")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'ipaexternalmember=%deref_r("member","ipaexternalmember")', u'objectclass=ipaexternalgroup', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'objectclass=posixGroup', u'gidNumber=%{gidNumber}', u'memberUid=%{memberUid}', u'memberUid=%deref_r("member","uid")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'ipaexternalmember=%deref_r("member","ipaexternalmember")', u'objectclass=ipaexternalgroup', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")'] 2019-01-17T11:00:49Z DEBUG add: 'ipaanchoruuid=%{ipaanchoruuid}' to schema-compat-entry-attribute, current value [u'objectclass=posixGroup', u'gidNumber=%{gidNumber}', u'memberUid=%{memberUid}', u'memberUid=%deref_r("member","uid")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'ipaexternalmember=%deref_r("member","ipaexternalmember")', u'objectclass=ipaexternalgroup', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'objectclass=posixGroup', u'gidNumber=%{gidNumber}', u'memberUid=%{memberUid}', u'memberUid=%deref_r("member","uid")', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'ipaexternalmember=%deref_r("member","ipaexternalmember")', u'objectclass=ipaexternalgroup', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}'] 2019-01-17T11:00:49Z DEBUG add: '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")' to schema-compat-entry-attribute, current value [u'objectclass=posixGroup', u'gidNumber=%{gidNumber}', u'memberUid=%{memberUid}', u'memberUid=%deref_r("member","uid")', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'ipaexternalmember=%deref_r("member","ipaexternalmember")', u'objectclass=ipaexternalgroup', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'objectclass=posixGroup', u'gidNumber=%{gidNumber}', u'memberUid=%{memberUid}', u'memberUid=%deref_r("member","uid")', u'ipaexternalmember=%deref_r("member","ipaexternalmember")', u'objectclass=ipaexternalgroup', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")'] 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:00:49Z DEBUG objectclass=posixGroup 2019-01-17T11:00:49Z DEBUG gidNumber=%{gidNumber} 2019-01-17T11:00:49Z DEBUG memberUid=%{memberUid} 2019-01-17T11:00:49Z DEBUG memberUid=%deref_r("member","uid") 2019-01-17T11:00:49Z DEBUG ipaexternalmember=%deref_r("member","ipaexternalmember") 2019-01-17T11:00:49Z DEBUG objectclass=ipaexternalgroup 2019-01-17T11:00:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:00:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","") 2019-01-17T11:00:49Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2019-01-17T11:00:49Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG groups 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG schema-compat-container-rdn: 2019-01-17T11:00:49Z DEBUG cn=groups 2019-01-17T11:00:49Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:00:49Z DEBUG dc=local 2019-01-17T11:00:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:00:49Z DEBUG cn=%{cn} 2019-01-17T11:00:49Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:00:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-search-filter: 2019-01-17T11:00:49Z DEBUG objectclass=posixGroup 2019-01-17T11:00:49Z DEBUG schema-compat-search-base: 2019-01-17T11:00:49Z DEBUG cn=groups, cn=accounts, dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-container-group: 2019-01-17T11:00:49Z DEBUG cn=compat, dc=local 2019-01-17T11:00:49Z DEBUG [] 2019-01-17T11:00:49Z DEBUG Updated 0 2019-01-17T11:00:49Z DEBUG Done 2019-01-17T11:00:49Z DEBUG Updating existing entry: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Initial value 2019-01-17T11:00:49Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:00:49Z DEBUG objectclass=posixAccount 2019-01-17T11:00:49Z DEBUG gecos=%{cn} 2019-01-17T11:00:49Z DEBUG cn=%{cn} 2019-01-17T11:00:49Z DEBUG uidNumber=%{uidNumber} 2019-01-17T11:00:49Z DEBUG gidNumber=%{gidNumber} 2019-01-17T11:00:49Z DEBUG loginShell=%{loginShell} 2019-01-17T11:00:49Z DEBUG homeDirectory=%{homeDirectory} 2019-01-17T11:00:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:00:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","") 2019-01-17T11:00:49Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2019-01-17T11:00:49Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:00:49Z DEBUG uid=%{uid} 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG users 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG schema-compat-container-rdn: 2019-01-17T11:00:49Z DEBUG cn=users 2019-01-17T11:00:49Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:00:49Z DEBUG dc=local 2019-01-17T11:00:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:00:49Z DEBUG uid=%first("%{uid}") 2019-01-17T11:00:49Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:00:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-search-filter: 2019-01-17T11:00:49Z DEBUG objectclass=posixAccount 2019-01-17T11:00:49Z DEBUG schema-compat-search-base: 2019-01-17T11:00:49Z DEBUG cn=users, cn=accounts, dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-container-group: 2019-01-17T11:00:49Z DEBUG cn=compat, dc=local 2019-01-17T11:00:49Z DEBUG add: 'uid=%{uid}' to schema-compat-entry-attribute, current value [u'objectclass=posixAccount', u'gecos=%{cn}', u'cn=%{cn}', u'uidNumber=%{uidNumber}', u'gidNumber=%{gidNumber}', u'loginShell=%{loginShell}', u'homeDirectory=%{homeDirectory}', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'uid=%{uid}'] 2019-01-17T11:00:49Z DEBUG add: updated value [u'objectclass=posixAccount', u'gecos=%{cn}', u'cn=%{cn}', u'uidNumber=%{uidNumber}', u'gidNumber=%{gidNumber}', u'loginShell=%{loginShell}', u'homeDirectory=%{homeDirectory}', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'uid=%{uid}'] 2019-01-17T11:00:49Z DEBUG replace: uid=%{uid} not found, skipping 2019-01-17T11:00:49Z DEBUG --------------------------------------------- 2019-01-17T11:00:49Z DEBUG Final value after applying updates 2019-01-17T11:00:49Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:00:49Z DEBUG objectclass=posixAccount 2019-01-17T11:00:49Z DEBUG gecos=%{cn} 2019-01-17T11:00:49Z DEBUG cn=%{cn} 2019-01-17T11:00:49Z DEBUG uidNumber=%{uidNumber} 2019-01-17T11:00:49Z DEBUG gidNumber=%{gidNumber} 2019-01-17T11:00:49Z DEBUG loginShell=%{loginShell} 2019-01-17T11:00:49Z DEBUG homeDirectory=%{homeDirectory} 2019-01-17T11:00:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:00:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","") 2019-01-17T11:00:49Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2019-01-17T11:00:49Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:00:49Z DEBUG uid=%{uid} 2019-01-17T11:00:49Z DEBUG cn: 2019-01-17T11:00:49Z DEBUG users 2019-01-17T11:00:49Z DEBUG objectClass: 2019-01-17T11:00:49Z DEBUG top 2019-01-17T11:00:49Z DEBUG extensibleObject 2019-01-17T11:00:49Z DEBUG schema-compat-container-rdn: 2019-01-17T11:00:49Z DEBUG cn=users 2019-01-17T11:00:49Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:00:49Z DEBUG dc=local 2019-01-17T11:00:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:00:49Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:00:49Z DEBUG uid=%first("%{uid}") 2019-01-17T11:00:49Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:00:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-search-filter: 2019-01-17T11:00:49Z DEBUG objectclass=posixAccount 2019-01-17T11:00:49Z DEBUG schema-compat-search-base: 2019-01-17T11:00:49Z DEBUG cn=users, cn=accounts, dc=local 2019-01-17T11:00:49Z DEBUG schema-compat-container-group: 2019-01-17T11:00:49Z DEBUG cn=compat, dc=local 2019-01-17T11:00:49Z DEBUG [] 2019-01-17T11:00:49Z DEBUG Updated 0 2019-01-17T11:00:49Z DEBUG Done 2019-01-17T11:00:49Z DEBUG Parsing update file '/usr/share/ipa/updates/90-post_upgrade_plugins.update' 2019-01-17T11:00:49Z DEBUG Executing upgrade plugin: update_ca_topology 2019-01-17T11:00:49Z DEBUG raw: update_ca_topology 2019-01-17T11:00:49Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:00:49Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2019-01-17T11:00:49Z DEBUG importing all plugin modules in ipaserver.plugins... 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.aci 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.automember 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.automount 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.baseldap 2019-01-17T11:00:49Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.baseuser 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.batch 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.ca 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.caacl 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.cert 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.certmap 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.certprofile 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.config 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.delegation 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.dns 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.dogtag 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.group 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.hbac 2019-01-17T11:00:49Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.hbactest 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.host 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.idrange 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.idviews 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.internal 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.join 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.ldap2 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.location 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.migration 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.misc 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.netgroup 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.otp 2019-01-17T11:00:49Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.otptoken 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.passwd 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.permission 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.ping 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.pkinit 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.privilege 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.rabase 2019-01-17T11:00:49Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.role 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.schema 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.selfservice 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.server 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.serverrole 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.serverroles 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.service 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.session 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.stageuser 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.sudo 2019-01-17T11:00:49Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.sudorule 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.topology 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.trust 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.user 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.vault 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.virtual 2019-01-17T11:00:49Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.whoami 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2019-01-17T11:00:49Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.install.plugins.dns 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2019-01-17T11:00:49Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2019-01-17T11:00:50Z DEBUG Created connection context.ldap2_140490511797072 2019-01-17T11:00:50Z DEBUG Destroyed connection context.ldap2_140490511797072 2019-01-17T11:00:50Z DEBUG Created connection context.ldap2_140490511797072 2019-01-17T11:00:50Z DEBUG Parsing update file '/usr/share/ipa/ca-topology.uldif' 2019-01-17T11:00:50Z DEBUG New entry: cn=centos75.local,cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:50Z DEBUG --------------------------------------------- 2019-01-17T11:00:50Z DEBUG Initial value 2019-01-17T11:00:50Z DEBUG dn: cn=centos75.local,cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:50Z DEBUG add: 'ipaReplTopoManagedServer' to objectclass, current value [] 2019-01-17T11:00:50Z DEBUG add: updated value [u'ipaReplTopoManagedServer'] 2019-01-17T11:00:50Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-LOCAL.socket from SchemaCache 2019-01-17T11:00:50Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LOCAL.socket conn= 2019-01-17T11:00:50Z DEBUG add: 'o=ipaca' to ipaReplTopoManagedSuffix, current value [] 2019-01-17T11:00:50Z DEBUG add: updated value [u'o=ipaca'] 2019-01-17T11:00:50Z DEBUG --------------------------------------------- 2019-01-17T11:00:50Z DEBUG Final value after applying updates 2019-01-17T11:00:50Z DEBUG dn: cn=centos75.local,cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:50Z DEBUG objectclass: 2019-01-17T11:00:50Z DEBUG ipaReplTopoManagedServer 2019-01-17T11:00:50Z DEBUG ipaReplTopoManagedSuffix: 2019-01-17T11:00:50Z DEBUG o=ipaca 2019-01-17T11:00:50Z ERROR Parent DN of cn=centos75.local,cn=masters,cn=ipa,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:50Z DEBUG New entry: cn=ca,cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:50Z DEBUG --------------------------------------------- 2019-01-17T11:00:50Z DEBUG Initial value 2019-01-17T11:00:50Z DEBUG dn: cn=ca,cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:50Z DEBUG objectclass: 2019-01-17T11:00:50Z DEBUG top 2019-01-17T11:00:50Z DEBUG iparepltopoconf 2019-01-17T11:00:50Z DEBUG cn: 2019-01-17T11:00:50Z DEBUG ca 2019-01-17T11:00:50Z DEBUG ipaReplTopoConfRoot: 2019-01-17T11:00:50Z DEBUG o=ipaca 2019-01-17T11:00:50Z DEBUG --------------------------------------------- 2019-01-17T11:00:50Z DEBUG Final value after applying updates 2019-01-17T11:00:50Z DEBUG dn: cn=ca,cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:00:50Z DEBUG objectclass: 2019-01-17T11:00:50Z DEBUG top 2019-01-17T11:00:50Z DEBUG iparepltopoconf 2019-01-17T11:00:50Z DEBUG cn: 2019-01-17T11:00:50Z DEBUG ca 2019-01-17T11:00:50Z DEBUG ipaReplTopoConfRoot: 2019-01-17T11:00:50Z DEBUG o=ipaca 2019-01-17T11:00:50Z ERROR Parent DN of cn=ca,cn=topology,cn=ipa,cn=etc,dc=local may not exist, cannot create the entry 2019-01-17T11:00:50Z DEBUG New entry: cn=replica,cn=o\=ipaca,cn=mapping tree,cn=config 2019-01-17T11:00:50Z DEBUG --------------------------------------------- 2019-01-17T11:00:50Z DEBUG Initial value 2019-01-17T11:00:50Z DEBUG dn: cn=replica,cn=o\=ipaca,cn=mapping tree,cn=config 2019-01-17T11:00:50Z DEBUG onlyifexist: 'cn=replication managers,cn=sysaccounts,cn=etc,dc=local' to nsds5replicabinddngroup, current value [] 2019-01-17T11:00:50Z DEBUG --------------------------------------------- 2019-01-17T11:00:50Z DEBUG Final value after applying updates 2019-01-17T11:00:50Z DEBUG dn: cn=replica,cn=o\=ipaca,cn=mapping tree,cn=config 2019-01-17T11:00:51Z DEBUG Destroyed connection context.ldap2_140490511797072 2019-01-17T11:00:51Z DEBUG Executing upgrade plugin: update_ipaconfigstring_dnsversion_to_ipadnsversion 2019-01-17T11:00:51Z DEBUG raw: update_ipaconfigstring_dnsversion_to_ipadnsversion 2019-01-17T11:00:51Z DEBUG Executing upgrade plugin: update_dnszones 2019-01-17T11:00:51Z DEBUG raw: update_dnszones 2019-01-17T11:00:51Z DEBUG Executing upgrade plugin: update_dns_limits 2019-01-17T11:00:51Z DEBUG raw: update_dns_limits 2019-01-17T11:00:51Z DEBUG Executing upgrade plugin: update_sigden_extdom_broken_config 2019-01-17T11:00:51Z DEBUG raw: update_sigden_extdom_broken_config 2019-01-17T11:00:51Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:00:51Z DEBUG Already done, skipping 2019-01-17T11:00:51Z DEBUG Executing upgrade plugin: update_sids 2019-01-17T11:00:51Z DEBUG raw: update_sids 2019-01-17T11:00:51Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:00:51Z DEBUG SIDs do not need to be generated 2019-01-17T11:00:51Z DEBUG Executing upgrade plugin: update_default_range 2019-01-17T11:00:51Z DEBUG raw: update_default_range 2019-01-17T11:00:51Z ERROR default_range: No local ID range and no admins group found. Cannot create default ID range 2019-01-17T11:00:51Z DEBUG Executing upgrade plugin: update_default_trust_view 2019-01-17T11:00:51Z DEBUG raw: update_default_trust_view 2019-01-17T11:00:51Z DEBUG raw: adtrust_is_enabled(version=u'2.229') 2019-01-17T11:00:51Z DEBUG adtrust_is_enabled(version=u'2.229') 2019-01-17T11:00:51Z DEBUG AD Trusts are not enabled on this server 2019-01-17T11:00:51Z DEBUG Executing upgrade plugin: update_tdo_gidnumber 2019-01-17T11:00:51Z DEBUG raw: update_tdo_gidnumber 2019-01-17T11:00:51Z DEBUG raw: adtrust_is_enabled(version=u'2.229') 2019-01-17T11:00:51Z DEBUG adtrust_is_enabled(version=u'2.229') 2019-01-17T11:00:51Z DEBUG AD Trusts are not enabled on this server 2019-01-17T11:00:51Z DEBUG Executing upgrade plugin: update_ca_renewal_master 2019-01-17T11:00:51Z DEBUG raw: update_ca_renewal_master 2019-01-17T11:00:51Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:00:51Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2019-01-17T11:00:51Z DEBUG found certmonger request for RA cert 2019-01-17T11:00:51Z DEBUG Executing upgrade plugin: update_idrange_type 2019-01-17T11:00:51Z DEBUG raw: update_idrange_type 2019-01-17T11:00:51Z DEBUG update_idrange_type: search for ID ranges with no type set 2019-01-17T11:00:51Z DEBUG update_idrange_type: no ID range without type set found 2019-01-17T11:00:51Z DEBUG Executing upgrade plugin: update_pacs 2019-01-17T11:00:51Z DEBUG raw: update_pacs 2019-01-17T11:00:51Z WARNING Error retrieving: cn=ipaConfig,cn=etc,dc=local 2019-01-17T11:00:51Z DEBUG Executing upgrade plugin: update_service_principalalias 2019-01-17T11:00:51Z DEBUG raw: update_service_principalalias 2019-01-17T11:00:51Z DEBUG update_service_principalalias: search for affected services 2019-01-17T11:00:51Z DEBUG update_service_principalalias: no service to update found 2019-01-17T11:00:51Z DEBUG Executing upgrade plugin: update_fix_duplicate_cacrt_in_ldap 2019-01-17T11:00:51Z DEBUG raw: update_fix_duplicate_cacrt_in_ldap 2019-01-17T11:00:51Z DEBUG raw: ca_is_enabled(version=u'2.229') 2019-01-17T11:00:51Z DEBUG ca_is_enabled(version=u'2.229') 2019-01-17T11:00:51Z DEBUG Destroyed connection context.ldap2_140490524145936 2019-01-17T11:00:51Z DEBUG Restarting directory server to apply updates 2019-01-17T11:00:51Z DEBUG Destroyed connection context.ldap2_140490554684880 2019-01-17T11:00:51Z DEBUG Starting external process 2019-01-17T11:00:51Z DEBUG args=/bin/systemctl restart dirsrv@LOCAL.service 2019-01-17T11:00:58Z DEBUG Process finished, return code=0 2019-01-17T11:00:58Z DEBUG stdout= 2019-01-17T11:00:58Z DEBUG stderr= 2019-01-17T11:00:58Z DEBUG Restart of dirsrv@LOCAL.service complete 2019-01-17T11:00:58Z DEBUG Created connection context.ldap2_140490554684880 2019-01-17T11:00:58Z DEBUG Created connection context.ldap2_140490524145936 2019-01-17T11:00:58Z DEBUG Executing upgrade plugin: update_upload_cacrt 2019-01-17T11:00:58Z DEBUG raw: update_upload_cacrt 2019-01-17T11:00:58Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2019-01-17T11:00:58Z DEBUG raw: ca_is_enabled(version=u'2.229') 2019-01-17T11:00:58Z DEBUG ca_is_enabled(version=u'2.229') 2019-01-17T11:00:58Z DEBUG Starting external process 2019-01-17T11:00:58Z DEBUG args=/usr/bin/certutil -d dbm:/etc/httpd/alias -L -f /etc/httpd/alias/pwdfile.txt 2019-01-17T11:00:58Z DEBUG Process finished, return code=0 2019-01-17T11:00:58Z DEBUG stdout= Certificate Nickname Trust Attributes SSL,S/MIME,JAR/XPI Server-Cert u,u,u LOCAL IPA CA CT,C,C 2019-01-17T11:00:58Z DEBUG stderr= 2019-01-17T11:00:58Z DEBUG Starting external process 2019-01-17T11:00:58Z DEBUG args=/usr/bin/certutil -d dbm:/etc/httpd/alias -O -n Server-Cert -f /etc/httpd/alias/pwdfile.txt 2019-01-17T11:00:58Z DEBUG Process finished, return code=0 2019-01-17T11:00:58Z DEBUG stdout="LOCAL IPA CA" [CN=Certificate Authority,O=LOCAL] "Server-Cert" [CN=centos75.local,O=LOCAL] 2019-01-17T11:00:58Z DEBUG stderr= 2019-01-17T11:00:58Z DEBUG Starting external process 2019-01-17T11:00:58Z DEBUG args=/usr/bin/certutil -d dbm:/etc/httpd/alias -L -f /etc/httpd/alias/pwdfile.txt 2019-01-17T11:00:58Z DEBUG Process finished, return code=0 2019-01-17T11:00:58Z DEBUG stdout= Certificate Nickname Trust Attributes SSL,S/MIME,JAR/XPI Server-Cert u,u,u LOCAL IPA CA CT,C,C 2019-01-17T11:00:58Z DEBUG stderr= 2019-01-17T11:00:58Z DEBUG Starting external process 2019-01-17T11:00:58Z DEBUG args=/usr/bin/certutil -d dbm:/etc/httpd/alias -L -n LOCAL IPA CA -a -f /etc/httpd/alias/pwdfile.txt 2019-01-17T11:00:58Z DEBUG Process finished, return code=0 2019-01-17T11:00:58Z DEBUG stdout=-----BEGIN CERTIFICATE----- MIIDeTCCAmGgAwIBAgIBATANBgkqhkiG9w0BAQsFADAwMQ4wDAYDVQQKDAVMT0NB TDEeMBwGA1UEAwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB4XDTE5MDExNzEwMzY0 MFoXDTM5MDExNzEwMzY0MFowMDEOMAwGA1UECgwFTE9DQUwxHjAcBgNVBAMMFUNl cnRpZmljYXRlIEF1dGhvcml0eTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoC ggEBAKZb97CB23Y/pVfUJDKG0Ul69AV+VipQ/VG6X4Xj16a07871RLLHMSx7p4dH kLmLe0R876dzQEE+z6fR0DXaCMISDlS9Bq9uVrAKKCYQRfT7O6TloVYbseh2os2h xdublLnJEZjwVDhyB6fhjfdx8GtPBETiLM37M7ZY9+6No+WkjSrPHlxPEzV/a8cB FN/iHQ1+5/Hbvc1NG5V67DJy+WLNRRYhMi9v7OSF8BbSl8ApHJMM0qYNLhvKuY5V N8nRDB0vwkea2cywI2wG9c2/vufzzh8F0MBMIpkL/LtanaBtZ0C6oSLsqGVBS+0q d8sQ5zZFAzdipndQd6xuzwmc6C0CAwEAAaOBnTCBmjAfBgNVHSMEGDAWgBRUEnLK tz1ZHkZQdIH6aDD/IGomxDAPBgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB/wQEAwIB xjAdBgNVHQ4EFgQUVBJyyrc9WR5GUHSB+mgw/yBqJsQwNwYIKwYBBQUHAQEEKzAp MCcGCCsGAQUFBzABhhtodHRwOi8vaXBhLWNhLmxvY2FsL2NhL29jc3AwDQYJKoZI hvcNAQELBQADggEBAI+bg4Nwz7fO3xdpD4X73ASnWPIWJoF3NX1qrn0vWjImbqyI gixTCWf2YXEGYYOU1czGj+M14HPVC8cKZBpobPY7ESZNDVrl07/iqkumdooibeqW KMo0UsOX9iNcnLtJdCXl7+yKlzUm16C8Ud+b0WuXmWwUg+DPf/xveYLw9058AoyA ODURXE1hx8J/tQKV03pmJ5CQfetVCxUyqUvHf50IV9+Td2fQAyIIt2rQExRn1R0a TmZPFeUVkbIDYITl79GQKHXSfJkCAFgzUR2EA0kmBZcCwzGM3Iqh1YUUQE9BPreb 3fWVexLT8Q7y4qP/qTxidd8SG0OGwFRkBH0fhFs= -----END CERTIFICATE----- 2019-01-17T11:00:58Z DEBUG stderr= 2019-01-17T11:00:58Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-LOCAL.socket from SchemaCache 2019-01-17T11:00:58Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LOCAL.socket conn= 2019-01-17T11:00:58Z DEBUG Destroyed connection context.ldap2_140490524145936 2019-01-17T11:00:58Z ERROR Upgrade failed with no such entry 2019-01-17T11:00:58Z DEBUG Traceback (most recent call last): File "/usr/lib/python2.7/site-packages/ipaserver/install/upgradeinstance.py", line 274, in __upgrade self.modified = (ld.update(self.files) or self.modified) File "/usr/lib/python2.7/site-packages/ipaserver/install/ldapupdate.py", line 952, in update self._run_updates(all_updates) File "/usr/lib/python2.7/site-packages/ipaserver/install/ldapupdate.py", line 924, in _run_updates self._run_update_plugin(update['plugin']) File "/usr/lib/python2.7/site-packages/ipaserver/install/ldapupdate.py", line 900, in _run_update_plugin restart_ds, updates = self.api.Updater[plugin_name]() File "/usr/lib/python2.7/site-packages/ipalib/frontend.py", line 1475, in __call__ return self.execute(**options) File "/usr/lib/python2.7/site-packages/ipaserver/install/plugins/upload_cacrt.py", line 98, in execute ldap.add_entry(entry) File "/usr/lib/python2.7/site-packages/ipapython/ipaldap.py", line 1569, in add_entry self.conn.add_s(str(entry.dn), list(attrs.items())) File "/usr/lib64/python2.7/contextlib.py", line 35, in __exit__ self.gen.throw(type, value, traceback) File "/usr/lib/python2.7/site-packages/ipapython/ipaldap.py", line 1017, in error_handler raise errors.NotFound(reason=arg_desc or 'no such entry') NotFound: no such entry 2019-01-17T11:00:58Z DEBUG Traceback (most recent call last): File "/usr/lib/python2.7/site-packages/ipaserver/install/service.py", line 570, in start_creation run_step(full_msg, method) File "/usr/lib/python2.7/site-packages/ipaserver/install/service.py", line 560, in run_step method() File "/usr/lib/python2.7/site-packages/ipaserver/install/upgradeinstance.py", line 282, in __upgrade raise RuntimeError(e) RuntimeError: no such entry 2019-01-17T11:00:58Z DEBUG [error] RuntimeError: no such entry 2019-01-17T11:00:58Z DEBUG [cleanup]: stopping directory server 2019-01-17T11:00:58Z DEBUG Destroyed connection context.ldap2_140490554684880 2019-01-17T11:00:58Z DEBUG Starting external process 2019-01-17T11:00:58Z DEBUG args=/bin/systemctl stop dirsrv@LOCAL.service 2019-01-17T11:01:00Z DEBUG Process finished, return code=0 2019-01-17T11:01:00Z DEBUG stdout= 2019-01-17T11:01:00Z DEBUG stderr= 2019-01-17T11:01:00Z DEBUG Stop of dirsrv@LOCAL.service complete 2019-01-17T11:01:00Z DEBUG duration: 1 seconds 2019-01-17T11:01:00Z DEBUG [cleanup]: restoring configuration 2019-01-17T11:01:00Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:01:00Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:01:00Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:01:00Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:01:00Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:01:00Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:01:00Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:01:00Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:01:00Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:01:00Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:01:00Z DEBUG duration: 0 seconds 2019-01-17T11:01:00Z ERROR IPA server upgrade failed: Inspect /var/log/ipaupgrade.log and run command ipa-server-upgrade manually. 2019-01-17T11:01:00Z DEBUG File "/usr/lib/python2.7/site-packages/ipapython/admintool.py", line 178, in execute return_value = self.run() File "/usr/lib/python2.7/site-packages/ipaserver/install/ipa_server_upgrade.py", line 56, in run raise admintool.ScriptError(str(e)) 2019-01-17T11:01:00Z DEBUG The ipa-server-upgrade command failed, exception: ScriptError: ('IPA upgrade failed.', 1) 2019-01-17T11:01:00Z ERROR ('IPA upgrade failed.', 1) 2019-01-17T11:01:00Z ERROR The ipa-server-upgrade command failed. See /var/log/ipaupgrade.log for more information 2019-01-17T11:03:01Z DEBUG Logging to /var/log/ipaupgrade.log 2019-01-17T11:03:01Z DEBUG ipa-server-upgrade was invoked with arguments [] and options: {'skip_version_check': False, 'log_file': None, 'force': False, 'verbose': False, 'quiet': False} 2019-01-17T11:03:01Z DEBUG IPA version 4.6.4-10.el7.centos 2019-01-17T11:03:01Z DEBUG importing all plugin modules in ipaserver.plugins... 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.aci 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.automember 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.automount 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.baseldap 2019-01-17T11:03:01Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.baseuser 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.batch 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.ca 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.caacl 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.cert 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.certmap 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.certprofile 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.config 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.delegation 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.dns 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.dogtag 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.group 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.hbac 2019-01-17T11:03:01Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.hbactest 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.host 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.idrange 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.idviews 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.internal 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.join 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.ldap2 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.location 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.migration 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.misc 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.netgroup 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.otp 2019-01-17T11:03:01Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.otptoken 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.passwd 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.permission 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.ping 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.pkinit 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.privilege 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.rabase 2019-01-17T11:03:01Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.role 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.schema 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.selfservice 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.server 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.serverrole 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.serverroles 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.service 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.session 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.stageuser 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.sudo 2019-01-17T11:03:01Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.sudorule 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.topology 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.trust 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.user 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.vault 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.virtual 2019-01-17T11:03:01Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.whoami 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2019-01-17T11:03:01Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.install.plugins.dns 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2019-01-17T11:03:01Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2019-01-17T11:03:02Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2019-01-17T11:03:02Z DEBUG Searching for an interface of IP address: ::1 2019-01-17T11:03:02Z DEBUG Testing local IP address: ::1/ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff (interface: lo) 2019-01-17T11:03:02Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:02Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:02Z INFO Missing version: no platform stored 2019-01-17T11:03:02Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:02Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2019-01-17T11:03:02Z DEBUG Starting external process 2019-01-17T11:03:02Z DEBUG args=/bin/systemctl is-active dirsrv@LOCAL.service 2019-01-17T11:03:02Z DEBUG Process finished, return code=3 2019-01-17T11:03:02Z DEBUG stdout=unknown 2019-01-17T11:03:02Z DEBUG stderr= 2019-01-17T11:03:02Z DEBUG Upgrading IPA:. Estimated time: 1 minute 30 seconds 2019-01-17T11:03:02Z DEBUG [1/9]: saving configuration 2019-01-17T11:03:02Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:02Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:02Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:02Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:02Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:02Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:02Z DEBUG duration: 0 seconds 2019-01-17T11:03:02Z DEBUG [2/9]: disabling listeners 2019-01-17T11:03:02Z DEBUG duration: 0 seconds 2019-01-17T11:03:02Z DEBUG [3/9]: enabling DS global lock 2019-01-17T11:03:02Z DEBUG duration: 0 seconds 2019-01-17T11:03:02Z DEBUG [4/9]: disabling Schema Compat 2019-01-17T11:03:03Z DEBUG duration: 0 seconds 2019-01-17T11:03:03Z DEBUG [5/9]: starting directory server 2019-01-17T11:03:03Z DEBUG Starting external process 2019-01-17T11:03:03Z DEBUG args=/bin/systemctl start dirsrv@LOCAL.service 2019-01-17T11:03:06Z DEBUG Process finished, return code=0 2019-01-17T11:03:06Z DEBUG stdout= 2019-01-17T11:03:06Z DEBUG stderr= 2019-01-17T11:03:06Z DEBUG Start of dirsrv@LOCAL.service complete 2019-01-17T11:03:06Z DEBUG Created connection context.ldap2_139822069897104 2019-01-17T11:03:06Z DEBUG duration: 3 seconds 2019-01-17T11:03:06Z DEBUG [6/9]: updating schema 2019-01-17T11:03:06Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-LOCAL.socket conn= 2019-01-17T11:03:07Z DEBUG Processing schema LDIF file /usr/share/ipa/60kerberos.ldif 2019-01-17T11:03:07Z DEBUG Processing schema LDIF file /usr/share/ipa/60samba.ldif 2019-01-17T11:03:07Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.24 NAME 'sambaLMPassword' DESC 'LanManager Password' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 SINGLE-VALUE X-ORIGIN ( 'IPA v4.6.4' 'user defined' ) ) 2019-01-17T11:03:07Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.24 NAME 'sambaLMPassword' DESC 'LanManager Password' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{32} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:03:07Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.20 NAME 'sambaSID' DESC 'Security ID' EQUALITY caseIgnoreIA5Match SUBSTR caseExactIA5SubstringsMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 SINGLE-VALUE X-ORIGIN ( 'IPA v4.6.4' 'user defined' ) ) 2019-01-17T11:03:07Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.20 NAME 'sambaSID' DESC 'Security ID' EQUALITY caseIgnoreIA5Match SUBSTR caseExactIA5SubstringsMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{64} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:03:07Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.38 NAME 'sambaDomainName' DESC 'Windows NT domain to which the user belongs' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN ( 'IPA v4.6.4' 'user defined' ) ) 2019-01-17T11:03:07Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.38 NAME 'sambaDomainName' DESC 'Windows NT domain to which the user belongs' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{128} X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:03:07Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.75 NAME 'sambaTrustAuthOutgoing' DESC 'Authentication information for the outgoing portion of a trust' EQUALITY caseExactMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN ( 'IPA v4.6.4' 'user defined' ) ) 2019-01-17T11:03:07Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.75 NAME 'sambaTrustAuthOutgoing' DESC 'Authentication information for the outgoing portion of a trust' EQUALITY caseExactMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{1050} X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:03:07Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.74 NAME 'sambaFlatName' DESC 'NetBIOS name of a domain' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN ( 'IPA v4.6.4' 'user defined' ) ) 2019-01-17T11:03:07Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.74 NAME 'sambaFlatName' DESC 'NetBIOS name of a domain' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{128} X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:03:07Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.76 NAME 'sambaTrustAuthIncoming' DESC 'Authentication information for the incoming portion of a trust' EQUALITY caseExactMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN ( 'IPA v4.6.4' 'user defined' ) ) 2019-01-17T11:03:07Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.76 NAME 'sambaTrustAuthIncoming' DESC 'Authentication information for the incoming portion of a trust' EQUALITY caseExactMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{1050} X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:03:07Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.77 NAME 'sambaSecurityIdentifier' DESC 'SID of a trusted domain' EQUALITY caseIgnoreIA5Match SUBSTR caseExactIA5SubstringsMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 SINGLE-VALUE X-ORIGIN ( 'IPA v4.6.4' 'user defined' ) ) 2019-01-17T11:03:07Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.77 NAME 'sambaSecurityIdentifier' DESC 'SID of a trusted domain' EQUALITY caseIgnoreIA5Match SUBSTR caseExactIA5SubstringsMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{64} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:03:07Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.73 NAME 'sambaTrustPartner' DESC 'Fully qualified name of the domain with which a trust exists' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN ( 'IPA v4.6.4' 'user defined' ) ) 2019-01-17T11:03:07Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.73 NAME 'sambaTrustPartner' DESC 'Fully qualified name of the domain with which a trust exists' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{128} X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:03:07Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.33 NAME 'sambaHomeDrive' DESC 'Driver letter of home directory mapping' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 SINGLE-VALUE X-ORIGIN ( 'IPA v4.6.4' 'user defined' ) ) 2019-01-17T11:03:07Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.33 NAME 'sambaHomeDrive' DESC 'Driver letter of home directory mapping' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{4} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:03:07Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.34 NAME 'sambaLogonScript' DESC 'Logon script path' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 SINGLE-VALUE X-ORIGIN ( 'IPA v4.6.4' 'user defined' ) ) 2019-01-17T11:03:07Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.34 NAME 'sambaLogonScript' DESC 'Logon script path' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{255} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:03:07Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.36 NAME 'sambaUserWorkstations' DESC 'List of user workstations the user is allowed to logon to' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 SINGLE-VALUE X-ORIGIN ( 'IPA v4.6.4' 'user defined' ) ) 2019-01-17T11:03:07Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.36 NAME 'sambaUserWorkstations' DESC 'List of user workstations the user is allowed to logon to' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{255} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:03:07Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.37 NAME 'sambaHomePath' DESC 'Home directory UNC path' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN ( 'IPA v4.6.4' 'user defined' ) ) 2019-01-17T11:03:07Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.37 NAME 'sambaHomePath' DESC 'Home directory UNC path' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{128} X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:03:07Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.25 NAME 'sambaNTPassword' DESC 'MD4 hash of the unicode password' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 SINGLE-VALUE X-ORIGIN ( 'IPA v4.6.4' 'user defined' ) ) 2019-01-17T11:03:07Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.25 NAME 'sambaNTPassword' DESC 'MD4 hash of the unicode password' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{32} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:03:07Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.23 NAME 'sambaPrimaryGroupSID' DESC 'Primary Group Security ID' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 SINGLE-VALUE X-ORIGIN ( 'IPA v4.6.4' 'user defined' ) ) 2019-01-17T11:03:07Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.23 NAME 'sambaPrimaryGroupSID' DESC 'Primary Group Security ID' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{64} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:03:07Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.55 NAME 'sambaLogonHours' DESC 'Logon Hours' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 SINGLE-VALUE X-ORIGIN ( 'IPA v4.6.4' 'user defined' ) ) 2019-01-17T11:03:07Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.55 NAME 'sambaLogonHours' DESC 'Logon Hours' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{42} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:03:07Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.47 NAME 'sambaMungedDial' DESC 'Base64 encoded user parameter string' EQUALITY caseExactMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN ( 'IPA v4.6.4' 'user defined' ) ) 2019-01-17T11:03:07Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.47 NAME 'sambaMungedDial' DESC 'Base64 encoded user parameter string' EQUALITY caseExactMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{1050} X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:03:07Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.78 NAME 'sambaTrustForestTrustInfo' DESC 'Forest trust information for a trusted domain object' EQUALITY caseExactMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN ( 'IPA v4.6.4' 'user defined' ) ) 2019-01-17T11:03:07Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.78 NAME 'sambaTrustForestTrustInfo' DESC 'Forest trust information for a trusted domain object' EQUALITY caseExactMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{1050} X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:03:07Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.35 NAME 'sambaProfilePath' DESC 'Roaming profile path' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 SINGLE-VALUE X-ORIGIN ( 'IPA v4.6.4' 'user defined' ) ) 2019-01-17T11:03:07Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.35 NAME 'sambaProfilePath' DESC 'Roaming profile path' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{255} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:03:07Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.54 NAME 'sambaPasswordHistory' DESC 'Concatenated MD5 hashes of the salted NT passwords used on this account' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 X-ORIGIN ( 'IPA v4.6.4' 'user defined' ) ) 2019-01-17T11:03:07Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.54 NAME 'sambaPasswordHistory' DESC 'Concatenated MD5 hashes of the salted NT passwords used on this account' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{32} X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:03:07Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.42 NAME 'sambaOptionName' DESC 'Option Name' EQUALITY caseIgnoreMatch SUBSTR caseIgnoreSubstringsMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN ( 'IPA v4.6.4' 'user defined' ) ) 2019-01-17T11:03:07Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.42 NAME 'sambaOptionName' DESC 'Option Name' EQUALITY caseIgnoreMatch SUBSTR caseIgnoreSubstringsMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{256} X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:03:07Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.51 NAME 'sambaSIDList' DESC 'Security ID List' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 X-ORIGIN ( 'IPA v4.6.4' 'user defined' ) ) 2019-01-17T11:03:07Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.51 NAME 'sambaSIDList' DESC 'Security ID List' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{64} X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:03:07Z DEBUG Replace: ( 1.3.6.1.4.1.7165.2.1.26 NAME 'sambaAcctFlags' DESC 'Account Flags' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 SINGLE-VALUE X-ORIGIN ( 'IPA v4.6.4' 'user defined' ) ) 2019-01-17T11:03:07Z DEBUG with: ( 1.3.6.1.4.1.7165.2.1.26 NAME 'sambaAcctFlags' DESC 'Account Flags' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{16} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:03:07Z DEBUG Schema modlist: [(0, u'attributetypes', ["( 1.3.6.1.4.1.7165.2.1.24 NAME 'sambaLMPassword' DESC 'LanManager Password' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{32} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.20 NAME 'sambaSID' DESC 'Security ID' EQUALITY caseIgnoreIA5Match SUBSTR caseExactIA5SubstringsMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{64} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.38 NAME 'sambaDomainName' DESC 'Windows NT domain to which the user belongs' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{128} X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.75 NAME 'sambaTrustAuthOutgoing' DESC 'Authentication information for the outgoing portion of a trust' EQUALITY caseExactMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{1050} X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.74 NAME 'sambaFlatName' DESC 'NetBIOS name of a domain' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{128} X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.76 NAME 'sambaTrustAuthIncoming' DESC 'Authentication information for the incoming portion of a trust' EQUALITY caseExactMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{1050} X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.77 NAME 'sambaSecurityIdentifier' DESC 'SID of a trusted domain' EQUALITY caseIgnoreIA5Match SUBSTR caseExactIA5SubstringsMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{64} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.73 NAME 'sambaTrustPartner' DESC 'Fully qualified name of the domain with which a trust exists' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{128} X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.33 NAME 'sambaHomeDrive' DESC 'Driver letter of home directory mapping' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{4} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.34 NAME 'sambaLogonScript' DESC 'Logon script path' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{255} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.36 NAME 'sambaUserWorkstations' DESC 'List of user workstations the user is allowed to logon to' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{255} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.37 NAME 'sambaHomePath' DESC 'Home directory UNC path' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{128} X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.25 NAME 'sambaNTPassword' DESC 'MD4 hash of the unicode password' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{32} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.23 NAME 'sambaPrimaryGroupSID' DESC 'Primary Group Security ID' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{64} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.55 NAME 'sambaLogonHours' DESC 'Logon Hours' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{42} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.47 NAME 'sambaMungedDial' DESC 'Base64 encoded user parameter string' EQUALITY caseExactMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{1050} X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.78 NAME 'sambaTrustForestTrustInfo' DESC 'Forest trust information for a trusted domain object' EQUALITY caseExactMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{1050} X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.35 NAME 'sambaProfilePath' DESC 'Roaming profile path' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{255} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.54 NAME 'sambaPasswordHistory' DESC 'Concatenated MD5 hashes of the salted NT passwords used on this account' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{32} X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.42 NAME 'sambaOptionName' DESC 'Option Name' EQUALITY caseIgnoreMatch SUBSTR caseIgnoreSubstringsMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{256} X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.51 NAME 'sambaSIDList' DESC 'Security ID List' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{64} X-ORIGIN 'IPA v4.6.4' )", "( 1.3.6.1.4.1.7165.2.1.26 NAME 'sambaAcctFlags' DESC 'Account Flags' EQUALITY caseIgnoreIA5Match SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{16} SINGLE-VALUE X-ORIGIN 'IPA v4.6.4' )"])] 2019-01-17T11:03:07Z DEBUG Processing schema LDIF file /usr/share/ipa/60ipaconfig.ldif 2019-01-17T11:03:07Z DEBUG Processing schema LDIF file /usr/share/ipa/60basev2.ldif 2019-01-17T11:03:07Z DEBUG Processing schema LDIF file /usr/share/ipa/60basev3.ldif 2019-01-17T11:03:07Z DEBUG Replace: ( 2.16.840.1.113730.3.8.11.51 NAME 'ipaAllowedToPerform' DESC 'DNs allowed to perform an operation' SUP distinguishedName EQUALITY distinguishedNameMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 X-ORIGIN ( 'IPA v4.0' 'user defined' ) ) 2019-01-17T11:03:07Z DEBUG with: ( 2.16.840.1.113730.3.8.11.51 NAME 'ipaAllowedToPerform' DESC 'DNs allowed to perform an operation' SUP distinguishedName X-ORIGIN 'IPA v4.0' ) 2019-01-17T11:03:07Z DEBUG Replace: ( 2.16.840.1.113730.3.8.11.14 NAME 'ipaNTTrustPartner' DESC 'Fully qualified name of the domain with which a trust exists' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN ( 'IPA v4.6.4' 'user defined' ) ) 2019-01-17T11:03:07Z DEBUG with: ( 2.16.840.1.113730.3.8.11.14 NAME 'ipaNTTrustPartner' DESC 'Fully qualified name of the domain with which a trust exists' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{128} X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:03:07Z DEBUG Replace: ( 2.16.840.1.113730.3.8.11.52 NAME 'ipaProtectedOperation' DESC 'Operation to be protected' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 X-ORIGIN ( 'IPA v4.6.4' 'user defined' ) ) 2019-01-17T11:03:07Z DEBUG with: ( 2.16.840.1.113730.3.8.11.52 NAME 'ipaProtectedOperation' DESC 'Operation to be protected' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{128} X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:03:07Z DEBUG Schema modlist: [(0, u'attributetypes', ["( 2.16.840.1.113730.3.8.11.51 NAME 'ipaAllowedToPerform' DESC 'DNs allowed to perform an operation' SUP distinguishedName X-ORIGIN 'IPA v4.0' )", "( 2.16.840.1.113730.3.8.11.14 NAME 'ipaNTTrustPartner' DESC 'Fully qualified name of the domain with which a trust exists' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{128} X-ORIGIN 'IPA v4.6.4' )", "( 2.16.840.1.113730.3.8.11.52 NAME 'ipaProtectedOperation' DESC 'Operation to be protected' EQUALITY caseIgnoreMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{128} X-ORIGIN 'IPA v4.6.4' )"])] 2019-01-17T11:03:08Z DEBUG Processing schema LDIF file /usr/share/ipa/60ipapk11.ldif 2019-01-17T11:03:08Z DEBUG Processing schema LDIF file /usr/share/ipa/60ipadns.ldif 2019-01-17T11:03:08Z DEBUG Processing schema LDIF file /usr/share/ipa/60certificate-profiles.ldif 2019-01-17T11:03:08Z DEBUG Replace: ( 2.16.840.1.113730.3.8.21.1.8 NAME 'ipaCaSubjectDN' DESC 'Subject DN' SUP distinguishedName EQUALITY distinguishedNameMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 X-ORIGIN ( 'IPA v4.4 Lightweight CAs' 'user defined' ) ) 2019-01-17T11:03:08Z DEBUG with: ( 2.16.840.1.113730.3.8.21.1.8 NAME 'ipaCaSubjectDN' DESC 'Subject DN' SUP distinguishedName X-ORIGIN 'IPA v4.4 Lightweight CAs' ) 2019-01-17T11:03:08Z DEBUG Replace: ( 2.16.840.1.113730.3.8.21.1.7 NAME 'ipaCaIssuerDN' DESC 'Issuer DN' SUP distinguishedName EQUALITY distinguishedNameMatch SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 X-ORIGIN ( 'IPA v4.4 Lightweight CAs' 'user defined' ) ) 2019-01-17T11:03:08Z DEBUG with: ( 2.16.840.1.113730.3.8.21.1.7 NAME 'ipaCaIssuerDN' DESC 'Issuer DN' SUP distinguishedName X-ORIGIN 'IPA v4.4 Lightweight CAs' ) 2019-01-17T11:03:08Z DEBUG Schema modlist: [(0, u'attributetypes', ["( 2.16.840.1.113730.3.8.21.1.8 NAME 'ipaCaSubjectDN' DESC 'Subject DN' SUP distinguishedName X-ORIGIN 'IPA v4.4 Lightweight CAs' )", "( 2.16.840.1.113730.3.8.21.1.7 NAME 'ipaCaIssuerDN' DESC 'Issuer DN' SUP distinguishedName X-ORIGIN 'IPA v4.4 Lightweight CAs' )"])] 2019-01-17T11:03:08Z DEBUG Replace: ( 2.16.840.1.113730.3.8.21.2.2 NAME 'ipaCaAcl' SUP ipaAssociation STRUCTURAL MAY ( ipaCaCategory $ ipaCertProfileCategory $ serviceCategory $ ipaMemberCa $ ipaMemberCertProfile $ memberService ) X-ORIGIN ( 'IPA v4.6.4' 'user defined' ) ) 2019-01-17T11:03:08Z DEBUG with: ( 2.16.840.1.113730.3.8.21.2.2 NAME 'ipaCaAcl' SUP ipaAssociation STRUCTURAL MUST cn MAY ( ipaCaCategory $ ipaCertProfileCategory $ userCategory $ hostCategory $ serviceCategory $ ipaMemberCa $ ipaMemberCertProfile $ memberService ) X-ORIGIN 'IPA v4.6.4' ) 2019-01-17T11:03:08Z DEBUG Schema modlist: [(0, u'objectclasses', ["( 2.16.840.1.113730.3.8.21.2.2 NAME 'ipaCaAcl' SUP ipaAssociation STRUCTURAL MUST cn MAY ( ipaCaCategory $ ipaCertProfileCategory $ userCategory $ hostCategory $ serviceCategory $ ipaMemberCa $ ipaMemberCertProfile $ memberService ) X-ORIGIN 'IPA v4.6.4' )"])] 2019-01-17T11:03:08Z DEBUG Processing schema LDIF file /usr/share/ipa/61kerberos-ipav3.ldif 2019-01-17T11:03:08Z DEBUG Processing schema LDIF file /usr/share/ipa/65ipacertstore.ldif 2019-01-17T11:03:08Z DEBUG Processing schema LDIF file /usr/share/ipa/65ipasudo.ldif 2019-01-17T11:03:08Z DEBUG Processing schema LDIF file /usr/share/ipa/70ipaotp.ldif 2019-01-17T11:03:08Z DEBUG Processing schema LDIF file /usr/share/ipa/70topology.ldif 2019-01-17T11:03:08Z DEBUG Processing schema LDIF file /usr/share/ipa/71idviews.ldif 2019-01-17T11:03:08Z DEBUG Processing schema LDIF file /usr/share/ipa/72domainlevels.ldif 2019-01-17T11:03:08Z DEBUG Processing schema LDIF file /usr/share/ipa/73certmap.ldif 2019-01-17T11:03:08Z DEBUG Processing schema LDIF file /usr/share/ipa/15rfc2307bis.ldif 2019-01-17T11:03:08Z DEBUG Processing schema LDIF file /usr/share/ipa/15rfc4876.ldif 2019-01-17T11:03:08Z DEBUG Processing schema LDIF file /usr/share/ipa/05rfc2247.ldif 2019-01-17T11:03:08Z DEBUG duration: 1 seconds 2019-01-17T11:03:08Z DEBUG [7/9]: upgrading server 2019-01-17T11:03:08Z DEBUG importing all plugin modules in ipaserver.plugins... 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.aci 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.automember 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.automount 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.baseldap 2019-01-17T11:03:08Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.baseuser 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.batch 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.ca 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.caacl 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.cert 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.certmap 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.certprofile 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.config 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.delegation 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.dns 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.dogtag 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.group 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.hbac 2019-01-17T11:03:08Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.hbactest 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.host 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.idrange 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.idviews 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.internal 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.join 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.ldap2 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.location 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.migration 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.misc 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.netgroup 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.otp 2019-01-17T11:03:08Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.otptoken 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.passwd 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.permission 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.ping 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.pkinit 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.privilege 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.rabase 2019-01-17T11:03:08Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.role 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.schema 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.selfservice 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.server 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.serverrole 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.serverroles 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.service 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.session 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.stageuser 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.sudo 2019-01-17T11:03:08Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.sudorule 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.topology 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.trust 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.user 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.vault 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.virtual 2019-01-17T11:03:08Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.whoami 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2019-01-17T11:03:08Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.install.plugins.dns 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2019-01-17T11:03:08Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2019-01-17T11:03:09Z DEBUG Created connection context.ldap2_139822039370512 2019-01-17T11:03:09Z DEBUG Destroyed connection context.ldap2_139822039370512 2019-01-17T11:03:09Z DEBUG Created connection context.ldap2_139822039370512 2019-01-17T11:03:09Z DEBUG Parsing update file '/usr/share/ipa/updates/05-pre_upgrade_plugins.update' 2019-01-17T11:03:09Z DEBUG Executing upgrade plugin: update_managed_post_first 2019-01-17T11:03:09Z DEBUG raw: update_managed_post_first 2019-01-17T11:03:09Z DEBUG Executing upgrade plugin: update_replica_attribute_lists 2019-01-17T11:03:09Z DEBUG raw: update_replica_attribute_lists 2019-01-17T11:03:09Z DEBUG Start replication agreement exclude list update task 2019-01-17T11:03:09Z DEBUG Found 0 agreement(s) 2019-01-17T11:03:09Z DEBUG Done updating agreements 2019-01-17T11:03:09Z DEBUG Executing upgrade plugin: update_passync_privilege_check 2019-01-17T11:03:09Z DEBUG raw: update_passync_privilege_check 2019-01-17T11:03:09Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:09Z DEBUG Check if there is existing PassSync privilege 2019-01-17T11:03:09Z DEBUG PassSync privilege not found, this is a new update 2019-01-17T11:03:09Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:09Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:09Z DEBUG Executing upgrade plugin: update_referint 2019-01-17T11:03:09Z DEBUG raw: update_referint 2019-01-17T11:03:09Z DEBUG Upgrading referential integrity plugin configuration 2019-01-17T11:03:09Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-LOCAL.socket from SchemaCache 2019-01-17T11:03:09Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LOCAL.socket conn= 2019-01-17T11:03:10Z DEBUG Initial value: LDAPEntry(ipapython.dn.DN('cn=referential integrity postoperation,cn=plugins,cn=config'), {u'cn': ['referential integrity postoperation'], u'nsslapd-pluginexcludeentryscope': ['cn=provisioning,dc=local'], u'nsslapd-pluginPath': ['libreferint-plugin'], u'nsslapd-plugin-depends-on-type': ['database'], u'nsslapd-pluginVendor': ['389 Project'], u'nsslapd-pluginprecedence': ['40'], u'nsslapd-pluginType': ['betxnpostoperation'], u'referint-logfile': ['/var/log/dirsrv/slapd-LOCAL/referint'], u'nsslapd-pluginInitfunc': ['referint_postop_init'], u'nsslapd-pluginVersion': ['1.3.8.4'], u'referint-update-delay': ['0'], u'nsslapd-plugincontainerscope': ['dc=local'], u'nsslapd-pluginDescription': ['referential integrity plugin'], u'nsslapd-pluginentryscope': ['dc=local'], u'nsslapd-pluginEnabled': ['on'], u'nsslapd-pluginId': ['referint'], u'objectClass': ['top', 'nsSlapdPlugin', 'extensibleObject'], u'referint-membership-attr': ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca', 'ipamembercertprofile', 'ipalocation']}) 2019-01-17T11:03:10Z DEBUG Plugin already uses new style, skipping 2019-01-17T11:03:10Z DEBUG Executing upgrade plugin: update_uniqueness_plugins_to_new_syntax 2019-01-17T11:03:10Z DEBUG raw: update_uniqueness_plugins_to_new_syntax 2019-01-17T11:03:10Z DEBUG No uniqueness plugin entries with old style configuration found 2019-01-17T11:03:10Z DEBUG Parsing update file '/usr/share/ipa/updates/10-config.update' 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-betype: 2019-01-17T11:03:10Z DEBUG ldbm database 2019-01-17T11:03:10Z DEBUG nsslapd-nagle: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-referralmode: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:03:10Z DEBUG 64 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 500 2019-01-17T11:03:10Z DEBUG passwordMinAlphas: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-readonly: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordLegacyPolicy: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:03:10Z DEBUG allowed 2019-01-17T11:03:10Z DEBUG passwordMinUppers: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-plugin: 2019-01-17T11:03:10Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:03:10Z DEBUG 20971520 2019-01-17T11:03:10Z DEBUG nsslapd-timelimit: 2019-01-17T11:03:10Z DEBUG 3600 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinTokenLength: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordMinAge: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:03:10Z DEBUG 60 2019-01-17T11:03:10Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:03:10Z DEBUG 1024 2019-01-17T11:03:10Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordInHistory: 2019-01-17T11:03:10Z DEBUG 6 2019-01-17T11:03:10Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-conntablesize: 2019-01-17T11:03:10Z DEBUG 16384 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-saslpath: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG passwordMaxAge: 2019-01-17T11:03:10Z DEBUG 8640000 2019-01-17T11:03:10Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:03:10Z DEBUG gidNumber 2019-01-17T11:03:10Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG day 2019-01-17T11:03:10Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-csnlogging: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-tmpdir: 2019-01-17T11:03:10Z DEBUG /tmp 2019-01-17T11:03:10Z DEBUG passwordResetFailureCount: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-counters: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-svrtab: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-minssf: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-schemadir: 2019-01-17T11:03:10Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:03:10Z DEBUG nsslapd-localuser: 2019-01-17T11:03:10Z DEBUG dirsrv 2019-01-17T11:03:10Z DEBUG nsslapd-security: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordChange: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-port 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:03:10Z DEBUG passwordMaxFailure: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:03:10Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:03:10Z DEBUG 128 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:03:10Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-rootdn: 2019-01-17T11:03:10Z DEBUG cn=Directory Manager 2019-01-17T11:03:10Z DEBUG nsslapd-ldifdir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:03:10Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordMustChange: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordExp: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-logging-backend: 2019-01-17T11:03:10Z DEBUG dirsrv-log 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:10Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:03:10Z DEBUG cn=Directory Manager 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinLength: 2019-01-17T11:03:10Z DEBUG 8 2019-01-17T11:03:10Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-idletimeout: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-securePort: 2019-01-17T11:03:10Z DEBUG 636 2019-01-17T11:03:10Z DEBUG nsslapd-snmp-index: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG config 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapdConfig 2019-01-17T11:03:10Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordSendExpiringTime: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-hash-filters: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:03:10Z DEBUG next 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-listenhost: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordCheckSyntax: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordGraceLimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG passwordWarning: 2019-01-17T11:03:10Z DEBUG 86400 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-instancedir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-config: 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-versionstring: 2019-01-17T11:03:10Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:03:10Z DEBUG 256 2019-01-17T11:03:10Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:03:10Z DEBUG SSHA512 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordLockout: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-lockdir: 2019-01-17T11:03:10Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-certdir: 2019-01-17T11:03:10Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 10 2019-01-17T11:03:10Z DEBUG nsslapd-backendconfig: 2019-01-17T11:03:10Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-threadnumber: 2019-01-17T11:03:10Z DEBUG 24 2019-01-17T11:03:10Z DEBUG nsslapd-schemamod: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-localhost: 2019-01-17T11:03:10Z DEBUG centos75.local 2019-01-17T11:03:10Z DEBUG nsslapd-bakdir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:03:10Z DEBUG passwordMin8bit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:03:10Z DEBUG uidNumber 2019-01-17T11:03:10Z DEBUG nsslapd-validate-cert: 2019-01-17T11:03:10Z DEBUG warn 2019-01-17T11:03:10Z DEBUG passwordMinCategories: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG passwordMinLowers: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordAdminDN: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordMinSpecials: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-lastmod: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:03:10Z DEBUG 40 2019-01-17T11:03:10Z DEBUG passwordMaxRepeats: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:03:10Z DEBUG -1 2019-01-17T11:03:10Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG nsslapd-result-tweak: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG passwordUnlock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-schemacheck: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-maxbersize: 2019-01-17T11:03:10Z DEBUG 209715200 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:03:10Z DEBUG dc=example,dc=com 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-localssf: 2019-01-17T11:03:10Z DEBUG 71 2019-01-17T11:03:10Z DEBUG nsslapd-sizelimit: 2019-01-17T11:03:10Z DEBUG 2000 2019-01-17T11:03:10Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG passwordLockoutDuration: 2019-01-17T11:03:10Z DEBUG 3600 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-port: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:03:10Z DEBUG cn=schema 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG cn=monitor 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-rootpw: 2019-01-17T11:03:10Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:03:10Z DEBUG 300000 2019-01-17T11:03:10Z DEBUG nsslapd-workingdir: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-rundir: 2019-01-17T11:03:10Z DEBUG /var/run/dirsrv 2019-01-17T11:03:10Z DEBUG nsslapd-schemareplace: 2019-01-17T11:03:10Z DEBUG replication-only 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:03:10Z DEBUG 16384 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:03:10Z DEBUG 10000 2019-01-17T11:03:10Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinDigits: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG passwordStorageScheme: 2019-01-17T11:03:10Z DEBUG SSHA512 2019-01-17T11:03:10Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG only: set nsslapd-ssl-check-hostname to 'on', current value [u'on'] 2019-01-17T11:03:10Z DEBUG only: updated value [u'on'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-betype: 2019-01-17T11:03:10Z DEBUG ldbm database 2019-01-17T11:03:10Z DEBUG nsslapd-nagle: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-referralmode: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:03:10Z DEBUG 64 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 500 2019-01-17T11:03:10Z DEBUG passwordMinAlphas: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-readonly: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordLegacyPolicy: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:03:10Z DEBUG allowed 2019-01-17T11:03:10Z DEBUG passwordMinUppers: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-plugin: 2019-01-17T11:03:10Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:03:10Z DEBUG 20971520 2019-01-17T11:03:10Z DEBUG nsslapd-timelimit: 2019-01-17T11:03:10Z DEBUG 3600 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinTokenLength: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordMinAge: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:03:10Z DEBUG 60 2019-01-17T11:03:10Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:03:10Z DEBUG 1024 2019-01-17T11:03:10Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordInHistory: 2019-01-17T11:03:10Z DEBUG 6 2019-01-17T11:03:10Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-conntablesize: 2019-01-17T11:03:10Z DEBUG 16384 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-saslpath: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG passwordMaxAge: 2019-01-17T11:03:10Z DEBUG 8640000 2019-01-17T11:03:10Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:03:10Z DEBUG gidNumber 2019-01-17T11:03:10Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG day 2019-01-17T11:03:10Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-csnlogging: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-tmpdir: 2019-01-17T11:03:10Z DEBUG /tmp 2019-01-17T11:03:10Z DEBUG passwordResetFailureCount: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-counters: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-svrtab: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-minssf: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-schemadir: 2019-01-17T11:03:10Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:03:10Z DEBUG nsslapd-localuser: 2019-01-17T11:03:10Z DEBUG dirsrv 2019-01-17T11:03:10Z DEBUG nsslapd-security: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordChange: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-port 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:03:10Z DEBUG passwordMaxFailure: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:03:10Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:03:10Z DEBUG 128 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:03:10Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-rootdn: 2019-01-17T11:03:10Z DEBUG cn=Directory Manager 2019-01-17T11:03:10Z DEBUG nsslapd-ldifdir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:03:10Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordMustChange: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordExp: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-logging-backend: 2019-01-17T11:03:10Z DEBUG dirsrv-log 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:10Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:03:10Z DEBUG cn=Directory Manager 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinLength: 2019-01-17T11:03:10Z DEBUG 8 2019-01-17T11:03:10Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-idletimeout: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-securePort: 2019-01-17T11:03:10Z DEBUG 636 2019-01-17T11:03:10Z DEBUG nsslapd-snmp-index: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG config 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapdConfig 2019-01-17T11:03:10Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordSendExpiringTime: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-hash-filters: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:03:10Z DEBUG next 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-listenhost: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordCheckSyntax: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordGraceLimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG passwordWarning: 2019-01-17T11:03:10Z DEBUG 86400 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-instancedir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-config: 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-versionstring: 2019-01-17T11:03:10Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:03:10Z DEBUG 256 2019-01-17T11:03:10Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:03:10Z DEBUG SSHA512 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordLockout: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-lockdir: 2019-01-17T11:03:10Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-certdir: 2019-01-17T11:03:10Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 10 2019-01-17T11:03:10Z DEBUG nsslapd-backendconfig: 2019-01-17T11:03:10Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-threadnumber: 2019-01-17T11:03:10Z DEBUG 24 2019-01-17T11:03:10Z DEBUG nsslapd-schemamod: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-localhost: 2019-01-17T11:03:10Z DEBUG centos75.local 2019-01-17T11:03:10Z DEBUG nsslapd-bakdir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:03:10Z DEBUG passwordMin8bit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:03:10Z DEBUG uidNumber 2019-01-17T11:03:10Z DEBUG nsslapd-validate-cert: 2019-01-17T11:03:10Z DEBUG warn 2019-01-17T11:03:10Z DEBUG passwordMinCategories: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG passwordMinLowers: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordAdminDN: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordMinSpecials: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-lastmod: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:03:10Z DEBUG 40 2019-01-17T11:03:10Z DEBUG passwordMaxRepeats: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:03:10Z DEBUG -1 2019-01-17T11:03:10Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG nsslapd-result-tweak: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG passwordUnlock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-schemacheck: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-maxbersize: 2019-01-17T11:03:10Z DEBUG 209715200 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:03:10Z DEBUG dc=example,dc=com 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-localssf: 2019-01-17T11:03:10Z DEBUG 71 2019-01-17T11:03:10Z DEBUG nsslapd-sizelimit: 2019-01-17T11:03:10Z DEBUG 2000 2019-01-17T11:03:10Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG passwordLockoutDuration: 2019-01-17T11:03:10Z DEBUG 3600 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-port: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:03:10Z DEBUG cn=schema 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG cn=monitor 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-rootpw: 2019-01-17T11:03:10Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:03:10Z DEBUG 300000 2019-01-17T11:03:10Z DEBUG nsslapd-workingdir: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-rundir: 2019-01-17T11:03:10Z DEBUG /var/run/dirsrv 2019-01-17T11:03:10Z DEBUG nsslapd-schemareplace: 2019-01-17T11:03:10Z DEBUG replication-only 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:03:10Z DEBUG 16384 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:03:10Z DEBUG 10000 2019-01-17T11:03:10Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinDigits: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG passwordStorageScheme: 2019-01-17T11:03:10Z DEBUG SSHA512 2019-01-17T11:03:10Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=Kerberos Principal Name,cn=IPA MODRDN,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=Kerberos Principal Name,cn=IPA MODRDN,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG Kerberos Principal Name 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG ipamodrdntargetattr: 2019-01-17T11:03:10Z DEBUG krbPrincipalName 2019-01-17T11:03:10Z DEBUG ipamodrdnsuffix: 2019-01-17T11:03:10Z DEBUG @LOCAL 2019-01-17T11:03:10Z DEBUG ipamodrdnsourceattr: 2019-01-17T11:03:10Z DEBUG uid 2019-01-17T11:03:10Z DEBUG ipamodrdnfilter: 2019-01-17T11:03:10Z DEBUG (&(objectclass=posixaccount)(objectclass=krbPrincipalAux)) 2019-01-17T11:03:10Z DEBUG ipamodrdnscope: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG remove: '60' from nsslapd-pluginPrecedence, current value [] 2019-01-17T11:03:10Z DEBUG remove: '60' not in nsslapd-pluginPrecedence 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=Kerberos Principal Name,cn=IPA MODRDN,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG Kerberos Principal Name 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG ipamodrdntargetattr: 2019-01-17T11:03:10Z DEBUG krbPrincipalName 2019-01-17T11:03:10Z DEBUG ipamodrdnsuffix: 2019-01-17T11:03:10Z DEBUG @LOCAL 2019-01-17T11:03:10Z DEBUG ipamodrdnsourceattr: 2019-01-17T11:03:10Z DEBUG uid 2019-01-17T11:03:10Z DEBUG ipamodrdnfilter: 2019-01-17T11:03:10Z DEBUG (&(objectclass=posixaccount)(objectclass=krbPrincipalAux)) 2019-01-17T11:03:10Z DEBUG ipamodrdnscope: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=IPA MODRDN,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=IPA MODRDN,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG IPA MODRDN 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG IPA MODRDN 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.0 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG IPA MODRDN plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libipa_modrdn 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG Red Hat, Inc. 2019-01-17T11:03:10Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:03:10Z DEBUG 60 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG betxnpostoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG ipamodrdn_init 2019-01-17T11:03:10Z DEBUG only: set nsslapd-pluginPrecedence to '60', current value [u'60'] 2019-01-17T11:03:10Z DEBUG only: updated value [u'60'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=IPA MODRDN,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG IPA MODRDN 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG IPA MODRDN 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.0 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG IPA MODRDN plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libipa_modrdn 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG Red Hat, Inc. 2019-01-17T11:03:10Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:03:10Z DEBUG 60 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG betxnpostoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG ipamodrdn_init 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-betype: 2019-01-17T11:03:10Z DEBUG ldbm database 2019-01-17T11:03:10Z DEBUG nsslapd-nagle: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-referralmode: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:03:10Z DEBUG 64 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 500 2019-01-17T11:03:10Z DEBUG passwordMinAlphas: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-readonly: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordLegacyPolicy: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:03:10Z DEBUG allowed 2019-01-17T11:03:10Z DEBUG passwordMinUppers: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-plugin: 2019-01-17T11:03:10Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:03:10Z DEBUG 20971520 2019-01-17T11:03:10Z DEBUG nsslapd-timelimit: 2019-01-17T11:03:10Z DEBUG 3600 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinTokenLength: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordMinAge: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:03:10Z DEBUG 60 2019-01-17T11:03:10Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:03:10Z DEBUG 1024 2019-01-17T11:03:10Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordInHistory: 2019-01-17T11:03:10Z DEBUG 6 2019-01-17T11:03:10Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-conntablesize: 2019-01-17T11:03:10Z DEBUG 16384 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-saslpath: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG passwordMaxAge: 2019-01-17T11:03:10Z DEBUG 8640000 2019-01-17T11:03:10Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:03:10Z DEBUG gidNumber 2019-01-17T11:03:10Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG day 2019-01-17T11:03:10Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-csnlogging: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-tmpdir: 2019-01-17T11:03:10Z DEBUG /tmp 2019-01-17T11:03:10Z DEBUG passwordResetFailureCount: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-counters: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-svrtab: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-minssf: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-schemadir: 2019-01-17T11:03:10Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:03:10Z DEBUG nsslapd-localuser: 2019-01-17T11:03:10Z DEBUG dirsrv 2019-01-17T11:03:10Z DEBUG nsslapd-security: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordChange: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-port 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:03:10Z DEBUG passwordMaxFailure: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:03:10Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:03:10Z DEBUG 128 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:03:10Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-rootdn: 2019-01-17T11:03:10Z DEBUG cn=Directory Manager 2019-01-17T11:03:10Z DEBUG nsslapd-ldifdir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:03:10Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordMustChange: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordExp: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-logging-backend: 2019-01-17T11:03:10Z DEBUG dirsrv-log 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:10Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:03:10Z DEBUG cn=Directory Manager 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinLength: 2019-01-17T11:03:10Z DEBUG 8 2019-01-17T11:03:10Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-idletimeout: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-securePort: 2019-01-17T11:03:10Z DEBUG 636 2019-01-17T11:03:10Z DEBUG nsslapd-snmp-index: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG config 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapdConfig 2019-01-17T11:03:10Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordSendExpiringTime: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-hash-filters: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:03:10Z DEBUG next 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-listenhost: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordCheckSyntax: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordGraceLimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG passwordWarning: 2019-01-17T11:03:10Z DEBUG 86400 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-instancedir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-config: 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-versionstring: 2019-01-17T11:03:10Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:03:10Z DEBUG 256 2019-01-17T11:03:10Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:03:10Z DEBUG SSHA512 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordLockout: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-lockdir: 2019-01-17T11:03:10Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-certdir: 2019-01-17T11:03:10Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 10 2019-01-17T11:03:10Z DEBUG nsslapd-backendconfig: 2019-01-17T11:03:10Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-threadnumber: 2019-01-17T11:03:10Z DEBUG 24 2019-01-17T11:03:10Z DEBUG nsslapd-schemamod: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-localhost: 2019-01-17T11:03:10Z DEBUG centos75.local 2019-01-17T11:03:10Z DEBUG nsslapd-bakdir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:03:10Z DEBUG passwordMin8bit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:03:10Z DEBUG uidNumber 2019-01-17T11:03:10Z DEBUG nsslapd-validate-cert: 2019-01-17T11:03:10Z DEBUG warn 2019-01-17T11:03:10Z DEBUG passwordMinCategories: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG passwordMinLowers: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordAdminDN: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordMinSpecials: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-lastmod: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:03:10Z DEBUG 40 2019-01-17T11:03:10Z DEBUG passwordMaxRepeats: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:03:10Z DEBUG -1 2019-01-17T11:03:10Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG nsslapd-result-tweak: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG passwordUnlock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-schemacheck: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-maxbersize: 2019-01-17T11:03:10Z DEBUG 209715200 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:03:10Z DEBUG dc=example,dc=com 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-localssf: 2019-01-17T11:03:10Z DEBUG 71 2019-01-17T11:03:10Z DEBUG nsslapd-sizelimit: 2019-01-17T11:03:10Z DEBUG 2000 2019-01-17T11:03:10Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG passwordLockoutDuration: 2019-01-17T11:03:10Z DEBUG 3600 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-port: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:03:10Z DEBUG cn=schema 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG cn=monitor 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-rootpw: 2019-01-17T11:03:10Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:03:10Z DEBUG 300000 2019-01-17T11:03:10Z DEBUG nsslapd-workingdir: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-rundir: 2019-01-17T11:03:10Z DEBUG /var/run/dirsrv 2019-01-17T11:03:10Z DEBUG nsslapd-schemareplace: 2019-01-17T11:03:10Z DEBUG replication-only 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:03:10Z DEBUG 16384 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:03:10Z DEBUG 10000 2019-01-17T11:03:10Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinDigits: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG passwordStorageScheme: 2019-01-17T11:03:10Z DEBUG SSHA512 2019-01-17T11:03:10Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-betype: 2019-01-17T11:03:10Z DEBUG ldbm database 2019-01-17T11:03:10Z DEBUG nsslapd-nagle: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-referralmode: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:03:10Z DEBUG 64 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 500 2019-01-17T11:03:10Z DEBUG passwordMinAlphas: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-readonly: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordLegacyPolicy: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:03:10Z DEBUG allowed 2019-01-17T11:03:10Z DEBUG passwordMinUppers: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-plugin: 2019-01-17T11:03:10Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:03:10Z DEBUG 20971520 2019-01-17T11:03:10Z DEBUG nsslapd-timelimit: 2019-01-17T11:03:10Z DEBUG 3600 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinTokenLength: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordMinAge: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:03:10Z DEBUG 60 2019-01-17T11:03:10Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:03:10Z DEBUG 1024 2019-01-17T11:03:10Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordInHistory: 2019-01-17T11:03:10Z DEBUG 6 2019-01-17T11:03:10Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-conntablesize: 2019-01-17T11:03:10Z DEBUG 16384 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-saslpath: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG passwordMaxAge: 2019-01-17T11:03:10Z DEBUG 8640000 2019-01-17T11:03:10Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:03:10Z DEBUG gidNumber 2019-01-17T11:03:10Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG day 2019-01-17T11:03:10Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-csnlogging: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-tmpdir: 2019-01-17T11:03:10Z DEBUG /tmp 2019-01-17T11:03:10Z DEBUG passwordResetFailureCount: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-counters: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-svrtab: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-minssf: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-schemadir: 2019-01-17T11:03:10Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:03:10Z DEBUG nsslapd-localuser: 2019-01-17T11:03:10Z DEBUG dirsrv 2019-01-17T11:03:10Z DEBUG nsslapd-security: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordChange: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-port 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:03:10Z DEBUG passwordMaxFailure: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:03:10Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:03:10Z DEBUG 128 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:03:10Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-rootdn: 2019-01-17T11:03:10Z DEBUG cn=Directory Manager 2019-01-17T11:03:10Z DEBUG nsslapd-ldifdir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:03:10Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordMustChange: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordExp: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-logging-backend: 2019-01-17T11:03:10Z DEBUG dirsrv-log 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:10Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:03:10Z DEBUG cn=Directory Manager 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinLength: 2019-01-17T11:03:10Z DEBUG 8 2019-01-17T11:03:10Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-idletimeout: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-securePort: 2019-01-17T11:03:10Z DEBUG 636 2019-01-17T11:03:10Z DEBUG nsslapd-snmp-index: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG config 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapdConfig 2019-01-17T11:03:10Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordSendExpiringTime: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-hash-filters: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:03:10Z DEBUG next 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-listenhost: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordCheckSyntax: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordGraceLimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG passwordWarning: 2019-01-17T11:03:10Z DEBUG 86400 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-instancedir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-config: 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-versionstring: 2019-01-17T11:03:10Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:03:10Z DEBUG 256 2019-01-17T11:03:10Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:03:10Z DEBUG SSHA512 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordLockout: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-lockdir: 2019-01-17T11:03:10Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-certdir: 2019-01-17T11:03:10Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 10 2019-01-17T11:03:10Z DEBUG nsslapd-backendconfig: 2019-01-17T11:03:10Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-threadnumber: 2019-01-17T11:03:10Z DEBUG 24 2019-01-17T11:03:10Z DEBUG nsslapd-schemamod: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-localhost: 2019-01-17T11:03:10Z DEBUG centos75.local 2019-01-17T11:03:10Z DEBUG nsslapd-bakdir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:03:10Z DEBUG passwordMin8bit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:03:10Z DEBUG uidNumber 2019-01-17T11:03:10Z DEBUG nsslapd-validate-cert: 2019-01-17T11:03:10Z DEBUG warn 2019-01-17T11:03:10Z DEBUG passwordMinCategories: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG passwordMinLowers: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordAdminDN: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordMinSpecials: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-lastmod: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:03:10Z DEBUG 40 2019-01-17T11:03:10Z DEBUG passwordMaxRepeats: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:03:10Z DEBUG -1 2019-01-17T11:03:10Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG nsslapd-result-tweak: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG passwordUnlock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-schemacheck: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-maxbersize: 2019-01-17T11:03:10Z DEBUG 209715200 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:03:10Z DEBUG dc=example,dc=com 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-localssf: 2019-01-17T11:03:10Z DEBUG 71 2019-01-17T11:03:10Z DEBUG nsslapd-sizelimit: 2019-01-17T11:03:10Z DEBUG 2000 2019-01-17T11:03:10Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG passwordLockoutDuration: 2019-01-17T11:03:10Z DEBUG 3600 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-port: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:03:10Z DEBUG cn=schema 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG cn=monitor 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-rootpw: 2019-01-17T11:03:10Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:03:10Z DEBUG 300000 2019-01-17T11:03:10Z DEBUG nsslapd-workingdir: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-rundir: 2019-01-17T11:03:10Z DEBUG /var/run/dirsrv 2019-01-17T11:03:10Z DEBUG nsslapd-schemareplace: 2019-01-17T11:03:10Z DEBUG replication-only 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:03:10Z DEBUG 16384 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:03:10Z DEBUG 10000 2019-01-17T11:03:10Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinDigits: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG passwordStorageScheme: 2019-01-17T11:03:10Z DEBUG SSHA512 2019-01-17T11:03:10Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=config,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=config,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-directory: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/db 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG config 2019-01-17T11:03:10Z DEBUG nsslapd-db-transaction-batch-val: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-lookthroughlimit: 2019-01-17T11:03:10Z DEBUG 100000 2019-01-17T11:03:10Z DEBUG nsslapd-db-deadlock-policy: 2019-01-17T11:03:10Z DEBUG 9 2019-01-17T11:03:10Z DEBUG nsslapd-db-transaction-batch-min-wait: 2019-01-17T11:03:10Z DEBUG 50 2019-01-17T11:03:10Z DEBUG nsslapd-db-locks: 2019-01-17T11:03:10Z DEBUG 50000 2019-01-17T11:03:10Z DEBUG nsslapd-serial-lock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-subtree-rename-switch: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-backend-opt-level: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-db-logdirectory: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/db 2019-01-17T11:03:10Z DEBUG nsslapd-exclude-from-export: 2019-01-17T11:03:10Z DEBUG entrydn entryid dncomp parentid numSubordinates tombstonenumsubordinates entryusn 2019-01-17T11:03:10Z DEBUG nsslapd-cache-autosize: 2019-01-17T11:03:10Z DEBUG 10 2019-01-17T11:03:10Z DEBUG nsslapd-db-transaction-batch-max-wait: 2019-01-17T11:03:10Z DEBUG 50 2019-01-17T11:03:10Z DEBUG nsslapd-rangelookthroughlimit: 2019-01-17T11:03:10Z DEBUG 5000 2019-01-17T11:03:10Z DEBUG nsslapd-dbcachesize: 2019-01-17T11:03:10Z DEBUG 20775403 2019-01-17T11:03:10Z DEBUG nsslapd-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-db-logbuf-size: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-import-cache-autosize: 2019-01-17T11:03:10Z DEBUG -1 2019-01-17T11:03:10Z DEBUG nsslapd-search-use-vlv-index: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pagedidlistscanlimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-idlistscanlimit: 2019-01-17T11:03:10Z DEBUG 100000 2019-01-17T11:03:10Z DEBUG nsslapd-search-bypass-filter-test: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-db-compactdb-interval: 2019-01-17T11:03:10Z DEBUG 2592000 2019-01-17T11:03:10Z DEBUG nsslapd-pagedlookthroughlimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-idl-switch: 2019-01-17T11:03:10Z DEBUG new 2019-01-17T11:03:10Z DEBUG nsslapd-db-durable-transaction: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-cache-autosize-split: 2019-01-17T11:03:10Z DEBUG 25 2019-01-17T11:03:10Z DEBUG nsslapd-db-private-import-mem: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-db-transaction-wait: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-db-checkpoint-interval: 2019-01-17T11:03:10Z DEBUG 60 2019-01-17T11:03:10Z DEBUG nsslapd-import-cachesize: 2019-01-17T11:03:10Z DEBUG 16777216 2019-01-17T11:03:10Z DEBUG replace: 5000 not found, skipping 2019-01-17T11:03:10Z DEBUG replace: 4000 not found, skipping 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=config,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-directory: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/db 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG config 2019-01-17T11:03:10Z DEBUG nsslapd-db-transaction-batch-val: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-lookthroughlimit: 2019-01-17T11:03:10Z DEBUG 100000 2019-01-17T11:03:10Z DEBUG nsslapd-db-deadlock-policy: 2019-01-17T11:03:10Z DEBUG 9 2019-01-17T11:03:10Z DEBUG nsslapd-db-transaction-batch-min-wait: 2019-01-17T11:03:10Z DEBUG 50 2019-01-17T11:03:10Z DEBUG nsslapd-db-locks: 2019-01-17T11:03:10Z DEBUG 50000 2019-01-17T11:03:10Z DEBUG nsslapd-serial-lock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-subtree-rename-switch: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-backend-opt-level: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-db-logdirectory: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/db 2019-01-17T11:03:10Z DEBUG nsslapd-exclude-from-export: 2019-01-17T11:03:10Z DEBUG entrydn entryid dncomp parentid numSubordinates tombstonenumsubordinates entryusn 2019-01-17T11:03:10Z DEBUG nsslapd-cache-autosize: 2019-01-17T11:03:10Z DEBUG 10 2019-01-17T11:03:10Z DEBUG nsslapd-db-transaction-batch-max-wait: 2019-01-17T11:03:10Z DEBUG 50 2019-01-17T11:03:10Z DEBUG nsslapd-rangelookthroughlimit: 2019-01-17T11:03:10Z DEBUG 5000 2019-01-17T11:03:10Z DEBUG nsslapd-dbcachesize: 2019-01-17T11:03:10Z DEBUG 20775403 2019-01-17T11:03:10Z DEBUG nsslapd-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-db-logbuf-size: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-import-cache-autosize: 2019-01-17T11:03:10Z DEBUG -1 2019-01-17T11:03:10Z DEBUG nsslapd-search-use-vlv-index: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pagedidlistscanlimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-idlistscanlimit: 2019-01-17T11:03:10Z DEBUG 100000 2019-01-17T11:03:10Z DEBUG nsslapd-search-bypass-filter-test: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-db-compactdb-interval: 2019-01-17T11:03:10Z DEBUG 2592000 2019-01-17T11:03:10Z DEBUG nsslapd-pagedlookthroughlimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-idl-switch: 2019-01-17T11:03:10Z DEBUG new 2019-01-17T11:03:10Z DEBUG nsslapd-db-durable-transaction: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-cache-autosize-split: 2019-01-17T11:03:10Z DEBUG 25 2019-01-17T11:03:10Z DEBUG nsslapd-db-private-import-mem: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-db-transaction-wait: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-db-checkpoint-interval: 2019-01-17T11:03:10Z DEBUG 60 2019-01-17T11:03:10Z DEBUG nsslapd-import-cachesize: 2019-01-17T11:03:10Z DEBUG 16777216 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG New entry: cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG objectclass: 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSizeLimit: 2019-01-17T11:03:10Z DEBUG 5000 2019-01-17T11:03:10Z DEBUG nsLookThroughLimit: 2019-01-17T11:03:10Z DEBUG 5000 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG anonymous-limits 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG objectclass: 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSizeLimit: 2019-01-17T11:03:10Z DEBUG 5000 2019-01-17T11:03:10Z DEBUG nsLookThroughLimit: 2019-01-17T11:03:10Z DEBUG 5000 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG anonymous-limits 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-betype: 2019-01-17T11:03:10Z DEBUG ldbm database 2019-01-17T11:03:10Z DEBUG nsslapd-nagle: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-referralmode: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:03:10Z DEBUG 64 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 500 2019-01-17T11:03:10Z DEBUG passwordMinAlphas: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-readonly: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordLegacyPolicy: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:03:10Z DEBUG allowed 2019-01-17T11:03:10Z DEBUG passwordMinUppers: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-plugin: 2019-01-17T11:03:10Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:03:10Z DEBUG 20971520 2019-01-17T11:03:10Z DEBUG nsslapd-timelimit: 2019-01-17T11:03:10Z DEBUG 3600 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinTokenLength: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordMinAge: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:03:10Z DEBUG 60 2019-01-17T11:03:10Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:03:10Z DEBUG 1024 2019-01-17T11:03:10Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordInHistory: 2019-01-17T11:03:10Z DEBUG 6 2019-01-17T11:03:10Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-conntablesize: 2019-01-17T11:03:10Z DEBUG 16384 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-saslpath: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG passwordMaxAge: 2019-01-17T11:03:10Z DEBUG 8640000 2019-01-17T11:03:10Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:03:10Z DEBUG gidNumber 2019-01-17T11:03:10Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG day 2019-01-17T11:03:10Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-csnlogging: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-tmpdir: 2019-01-17T11:03:10Z DEBUG /tmp 2019-01-17T11:03:10Z DEBUG passwordResetFailureCount: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-counters: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-svrtab: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-minssf: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-schemadir: 2019-01-17T11:03:10Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:03:10Z DEBUG nsslapd-localuser: 2019-01-17T11:03:10Z DEBUG dirsrv 2019-01-17T11:03:10Z DEBUG nsslapd-security: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordChange: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-port 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:03:10Z DEBUG passwordMaxFailure: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:03:10Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:03:10Z DEBUG 128 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:03:10Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-rootdn: 2019-01-17T11:03:10Z DEBUG cn=Directory Manager 2019-01-17T11:03:10Z DEBUG nsslapd-ldifdir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:03:10Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordMustChange: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordExp: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-logging-backend: 2019-01-17T11:03:10Z DEBUG dirsrv-log 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:10Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:03:10Z DEBUG cn=Directory Manager 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinLength: 2019-01-17T11:03:10Z DEBUG 8 2019-01-17T11:03:10Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-idletimeout: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-securePort: 2019-01-17T11:03:10Z DEBUG 636 2019-01-17T11:03:10Z DEBUG nsslapd-snmp-index: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG config 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapdConfig 2019-01-17T11:03:10Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordSendExpiringTime: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-hash-filters: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:03:10Z DEBUG next 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-listenhost: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordCheckSyntax: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordGraceLimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG passwordWarning: 2019-01-17T11:03:10Z DEBUG 86400 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-instancedir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-config: 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-versionstring: 2019-01-17T11:03:10Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:03:10Z DEBUG 256 2019-01-17T11:03:10Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:03:10Z DEBUG SSHA512 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordLockout: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-lockdir: 2019-01-17T11:03:10Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-certdir: 2019-01-17T11:03:10Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 10 2019-01-17T11:03:10Z DEBUG nsslapd-backendconfig: 2019-01-17T11:03:10Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-threadnumber: 2019-01-17T11:03:10Z DEBUG 24 2019-01-17T11:03:10Z DEBUG nsslapd-schemamod: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-localhost: 2019-01-17T11:03:10Z DEBUG centos75.local 2019-01-17T11:03:10Z DEBUG nsslapd-bakdir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:03:10Z DEBUG passwordMin8bit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:03:10Z DEBUG uidNumber 2019-01-17T11:03:10Z DEBUG nsslapd-validate-cert: 2019-01-17T11:03:10Z DEBUG warn 2019-01-17T11:03:10Z DEBUG passwordMinCategories: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG passwordMinLowers: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordAdminDN: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordMinSpecials: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-lastmod: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:03:10Z DEBUG 40 2019-01-17T11:03:10Z DEBUG passwordMaxRepeats: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:03:10Z DEBUG -1 2019-01-17T11:03:10Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG nsslapd-result-tweak: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG passwordUnlock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-schemacheck: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-maxbersize: 2019-01-17T11:03:10Z DEBUG 209715200 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:03:10Z DEBUG dc=example,dc=com 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-localssf: 2019-01-17T11:03:10Z DEBUG 71 2019-01-17T11:03:10Z DEBUG nsslapd-sizelimit: 2019-01-17T11:03:10Z DEBUG 2000 2019-01-17T11:03:10Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG passwordLockoutDuration: 2019-01-17T11:03:10Z DEBUG 3600 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-port: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:03:10Z DEBUG cn=schema 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG cn=monitor 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-rootpw: 2019-01-17T11:03:10Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:03:10Z DEBUG 300000 2019-01-17T11:03:10Z DEBUG nsslapd-workingdir: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-rundir: 2019-01-17T11:03:10Z DEBUG /var/run/dirsrv 2019-01-17T11:03:10Z DEBUG nsslapd-schemareplace: 2019-01-17T11:03:10Z DEBUG replication-only 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:03:10Z DEBUG 16384 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:03:10Z DEBUG 10000 2019-01-17T11:03:10Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinDigits: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG passwordStorageScheme: 2019-01-17T11:03:10Z DEBUG SSHA512 2019-01-17T11:03:10Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG only: set nsslapd-anonlimitsdn to 'cn=anonymous-limits,cn=etc,dc=local', current value [u'cn=anonymous-limits,cn=etc,dc=local'] 2019-01-17T11:03:10Z DEBUG only: updated value [u'cn=anonymous-limits,cn=etc,dc=local'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-betype: 2019-01-17T11:03:10Z DEBUG ldbm database 2019-01-17T11:03:10Z DEBUG nsslapd-nagle: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-referralmode: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:03:10Z DEBUG 64 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 500 2019-01-17T11:03:10Z DEBUG passwordMinAlphas: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-readonly: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordLegacyPolicy: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:03:10Z DEBUG allowed 2019-01-17T11:03:10Z DEBUG passwordMinUppers: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-plugin: 2019-01-17T11:03:10Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:03:10Z DEBUG 20971520 2019-01-17T11:03:10Z DEBUG nsslapd-timelimit: 2019-01-17T11:03:10Z DEBUG 3600 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinTokenLength: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordMinAge: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:03:10Z DEBUG 60 2019-01-17T11:03:10Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:03:10Z DEBUG 1024 2019-01-17T11:03:10Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordInHistory: 2019-01-17T11:03:10Z DEBUG 6 2019-01-17T11:03:10Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-conntablesize: 2019-01-17T11:03:10Z DEBUG 16384 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-saslpath: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG passwordMaxAge: 2019-01-17T11:03:10Z DEBUG 8640000 2019-01-17T11:03:10Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:03:10Z DEBUG gidNumber 2019-01-17T11:03:10Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG day 2019-01-17T11:03:10Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-csnlogging: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-tmpdir: 2019-01-17T11:03:10Z DEBUG /tmp 2019-01-17T11:03:10Z DEBUG passwordResetFailureCount: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-counters: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-svrtab: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-minssf: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-schemadir: 2019-01-17T11:03:10Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:03:10Z DEBUG nsslapd-localuser: 2019-01-17T11:03:10Z DEBUG dirsrv 2019-01-17T11:03:10Z DEBUG nsslapd-security: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordChange: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-port 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:03:10Z DEBUG passwordMaxFailure: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:03:10Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:03:10Z DEBUG 128 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:03:10Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-rootdn: 2019-01-17T11:03:10Z DEBUG cn=Directory Manager 2019-01-17T11:03:10Z DEBUG nsslapd-ldifdir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:03:10Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordMustChange: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordExp: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-logging-backend: 2019-01-17T11:03:10Z DEBUG dirsrv-log 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:10Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:03:10Z DEBUG cn=Directory Manager 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinLength: 2019-01-17T11:03:10Z DEBUG 8 2019-01-17T11:03:10Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-idletimeout: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-securePort: 2019-01-17T11:03:10Z DEBUG 636 2019-01-17T11:03:10Z DEBUG nsslapd-snmp-index: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG config 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapdConfig 2019-01-17T11:03:10Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordSendExpiringTime: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-hash-filters: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:03:10Z DEBUG next 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-listenhost: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordCheckSyntax: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordGraceLimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG passwordWarning: 2019-01-17T11:03:10Z DEBUG 86400 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-instancedir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-config: 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-versionstring: 2019-01-17T11:03:10Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:03:10Z DEBUG 256 2019-01-17T11:03:10Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:03:10Z DEBUG SSHA512 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordLockout: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-lockdir: 2019-01-17T11:03:10Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-certdir: 2019-01-17T11:03:10Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 10 2019-01-17T11:03:10Z DEBUG nsslapd-backendconfig: 2019-01-17T11:03:10Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-threadnumber: 2019-01-17T11:03:10Z DEBUG 24 2019-01-17T11:03:10Z DEBUG nsslapd-schemamod: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-localhost: 2019-01-17T11:03:10Z DEBUG centos75.local 2019-01-17T11:03:10Z DEBUG nsslapd-bakdir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:03:10Z DEBUG passwordMin8bit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:03:10Z DEBUG uidNumber 2019-01-17T11:03:10Z DEBUG nsslapd-validate-cert: 2019-01-17T11:03:10Z DEBUG warn 2019-01-17T11:03:10Z DEBUG passwordMinCategories: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG passwordMinLowers: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordAdminDN: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordMinSpecials: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-lastmod: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:03:10Z DEBUG 40 2019-01-17T11:03:10Z DEBUG passwordMaxRepeats: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:03:10Z DEBUG -1 2019-01-17T11:03:10Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG nsslapd-result-tweak: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG passwordUnlock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-schemacheck: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-maxbersize: 2019-01-17T11:03:10Z DEBUG 209715200 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:03:10Z DEBUG dc=example,dc=com 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-localssf: 2019-01-17T11:03:10Z DEBUG 71 2019-01-17T11:03:10Z DEBUG nsslapd-sizelimit: 2019-01-17T11:03:10Z DEBUG 2000 2019-01-17T11:03:10Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG passwordLockoutDuration: 2019-01-17T11:03:10Z DEBUG 3600 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-port: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:03:10Z DEBUG cn=schema 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG cn=monitor 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-rootpw: 2019-01-17T11:03:10Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:03:10Z DEBUG 300000 2019-01-17T11:03:10Z DEBUG nsslapd-workingdir: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-rundir: 2019-01-17T11:03:10Z DEBUG /var/run/dirsrv 2019-01-17T11:03:10Z DEBUG nsslapd-schemareplace: 2019-01-17T11:03:10Z DEBUG replication-only 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:03:10Z DEBUG 16384 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:03:10Z DEBUG 10000 2019-01-17T11:03:10Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinDigits: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG passwordStorageScheme: 2019-01-17T11:03:10Z DEBUG SSHA512 2019-01-17T11:03:10Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-betype: 2019-01-17T11:03:10Z DEBUG ldbm database 2019-01-17T11:03:10Z DEBUG nsslapd-nagle: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-referralmode: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:03:10Z DEBUG 64 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 500 2019-01-17T11:03:10Z DEBUG passwordMinAlphas: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-readonly: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordLegacyPolicy: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:03:10Z DEBUG allowed 2019-01-17T11:03:10Z DEBUG passwordMinUppers: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-plugin: 2019-01-17T11:03:10Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:03:10Z DEBUG 20971520 2019-01-17T11:03:10Z DEBUG nsslapd-timelimit: 2019-01-17T11:03:10Z DEBUG 3600 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinTokenLength: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordMinAge: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:03:10Z DEBUG 60 2019-01-17T11:03:10Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:03:10Z DEBUG 1024 2019-01-17T11:03:10Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordInHistory: 2019-01-17T11:03:10Z DEBUG 6 2019-01-17T11:03:10Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-conntablesize: 2019-01-17T11:03:10Z DEBUG 16384 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-saslpath: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG passwordMaxAge: 2019-01-17T11:03:10Z DEBUG 8640000 2019-01-17T11:03:10Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:03:10Z DEBUG gidNumber 2019-01-17T11:03:10Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG day 2019-01-17T11:03:10Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-csnlogging: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-tmpdir: 2019-01-17T11:03:10Z DEBUG /tmp 2019-01-17T11:03:10Z DEBUG passwordResetFailureCount: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-counters: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-svrtab: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-minssf: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-schemadir: 2019-01-17T11:03:10Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:03:10Z DEBUG nsslapd-localuser: 2019-01-17T11:03:10Z DEBUG dirsrv 2019-01-17T11:03:10Z DEBUG nsslapd-security: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordChange: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-port 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:03:10Z DEBUG passwordMaxFailure: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:03:10Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:03:10Z DEBUG 128 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:03:10Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-rootdn: 2019-01-17T11:03:10Z DEBUG cn=Directory Manager 2019-01-17T11:03:10Z DEBUG nsslapd-ldifdir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:03:10Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordMustChange: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordExp: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-logging-backend: 2019-01-17T11:03:10Z DEBUG dirsrv-log 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:10Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:03:10Z DEBUG cn=Directory Manager 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinLength: 2019-01-17T11:03:10Z DEBUG 8 2019-01-17T11:03:10Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-idletimeout: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-securePort: 2019-01-17T11:03:10Z DEBUG 636 2019-01-17T11:03:10Z DEBUG nsslapd-snmp-index: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG config 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapdConfig 2019-01-17T11:03:10Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordSendExpiringTime: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-hash-filters: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:03:10Z DEBUG next 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-listenhost: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordCheckSyntax: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordGraceLimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG passwordWarning: 2019-01-17T11:03:10Z DEBUG 86400 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-instancedir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-config: 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-versionstring: 2019-01-17T11:03:10Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:03:10Z DEBUG 256 2019-01-17T11:03:10Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:03:10Z DEBUG SSHA512 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordLockout: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-lockdir: 2019-01-17T11:03:10Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-certdir: 2019-01-17T11:03:10Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 10 2019-01-17T11:03:10Z DEBUG nsslapd-backendconfig: 2019-01-17T11:03:10Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-threadnumber: 2019-01-17T11:03:10Z DEBUG 24 2019-01-17T11:03:10Z DEBUG nsslapd-schemamod: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-localhost: 2019-01-17T11:03:10Z DEBUG centos75.local 2019-01-17T11:03:10Z DEBUG nsslapd-bakdir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:03:10Z DEBUG passwordMin8bit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:03:10Z DEBUG uidNumber 2019-01-17T11:03:10Z DEBUG nsslapd-validate-cert: 2019-01-17T11:03:10Z DEBUG warn 2019-01-17T11:03:10Z DEBUG passwordMinCategories: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG passwordMinLowers: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordAdminDN: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordMinSpecials: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-lastmod: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:03:10Z DEBUG 40 2019-01-17T11:03:10Z DEBUG passwordMaxRepeats: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:03:10Z DEBUG -1 2019-01-17T11:03:10Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG nsslapd-result-tweak: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG passwordUnlock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-schemacheck: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-maxbersize: 2019-01-17T11:03:10Z DEBUG 209715200 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:03:10Z DEBUG dc=example,dc=com 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-localssf: 2019-01-17T11:03:10Z DEBUG 71 2019-01-17T11:03:10Z DEBUG nsslapd-sizelimit: 2019-01-17T11:03:10Z DEBUG 2000 2019-01-17T11:03:10Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG passwordLockoutDuration: 2019-01-17T11:03:10Z DEBUG 3600 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-port: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:03:10Z DEBUG cn=schema 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG cn=monitor 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-rootpw: 2019-01-17T11:03:10Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:03:10Z DEBUG 300000 2019-01-17T11:03:10Z DEBUG nsslapd-workingdir: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-rundir: 2019-01-17T11:03:10Z DEBUG /var/run/dirsrv 2019-01-17T11:03:10Z DEBUG nsslapd-schemareplace: 2019-01-17T11:03:10Z DEBUG replication-only 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:03:10Z DEBUG 16384 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:03:10Z DEBUG 10000 2019-01-17T11:03:10Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinDigits: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG passwordStorageScheme: 2019-01-17T11:03:10Z DEBUG SSHA512 2019-01-17T11:03:10Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG add: 'dc=local' to nsslapd-defaultNamingContext, current value [u'dc=local'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'dc=local'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-betype: 2019-01-17T11:03:10Z DEBUG ldbm database 2019-01-17T11:03:10Z DEBUG nsslapd-nagle: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-referralmode: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:03:10Z DEBUG 64 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 500 2019-01-17T11:03:10Z DEBUG passwordMinAlphas: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-readonly: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordLegacyPolicy: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:03:10Z DEBUG allowed 2019-01-17T11:03:10Z DEBUG passwordMinUppers: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-plugin: 2019-01-17T11:03:10Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:03:10Z DEBUG 20971520 2019-01-17T11:03:10Z DEBUG nsslapd-timelimit: 2019-01-17T11:03:10Z DEBUG 3600 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinTokenLength: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordMinAge: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:03:10Z DEBUG 60 2019-01-17T11:03:10Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:03:10Z DEBUG 1024 2019-01-17T11:03:10Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordInHistory: 2019-01-17T11:03:10Z DEBUG 6 2019-01-17T11:03:10Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-conntablesize: 2019-01-17T11:03:10Z DEBUG 16384 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-saslpath: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG passwordMaxAge: 2019-01-17T11:03:10Z DEBUG 8640000 2019-01-17T11:03:10Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:03:10Z DEBUG gidNumber 2019-01-17T11:03:10Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG day 2019-01-17T11:03:10Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-csnlogging: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-tmpdir: 2019-01-17T11:03:10Z DEBUG /tmp 2019-01-17T11:03:10Z DEBUG passwordResetFailureCount: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-counters: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-svrtab: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-minssf: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-schemadir: 2019-01-17T11:03:10Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:03:10Z DEBUG nsslapd-localuser: 2019-01-17T11:03:10Z DEBUG dirsrv 2019-01-17T11:03:10Z DEBUG nsslapd-security: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordChange: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-port 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:03:10Z DEBUG passwordMaxFailure: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:03:10Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:03:10Z DEBUG 128 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:03:10Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-rootdn: 2019-01-17T11:03:10Z DEBUG cn=Directory Manager 2019-01-17T11:03:10Z DEBUG nsslapd-ldifdir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:03:10Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordMustChange: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordExp: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-logging-backend: 2019-01-17T11:03:10Z DEBUG dirsrv-log 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:10Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:03:10Z DEBUG cn=Directory Manager 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinLength: 2019-01-17T11:03:10Z DEBUG 8 2019-01-17T11:03:10Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-idletimeout: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-securePort: 2019-01-17T11:03:10Z DEBUG 636 2019-01-17T11:03:10Z DEBUG nsslapd-snmp-index: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG config 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapdConfig 2019-01-17T11:03:10Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordSendExpiringTime: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-hash-filters: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:03:10Z DEBUG next 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-listenhost: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordCheckSyntax: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordGraceLimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG passwordWarning: 2019-01-17T11:03:10Z DEBUG 86400 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-instancedir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-config: 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-versionstring: 2019-01-17T11:03:10Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:03:10Z DEBUG 256 2019-01-17T11:03:10Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:03:10Z DEBUG SSHA512 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordLockout: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-lockdir: 2019-01-17T11:03:10Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-certdir: 2019-01-17T11:03:10Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 10 2019-01-17T11:03:10Z DEBUG nsslapd-backendconfig: 2019-01-17T11:03:10Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-threadnumber: 2019-01-17T11:03:10Z DEBUG 24 2019-01-17T11:03:10Z DEBUG nsslapd-schemamod: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-localhost: 2019-01-17T11:03:10Z DEBUG centos75.local 2019-01-17T11:03:10Z DEBUG nsslapd-bakdir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:03:10Z DEBUG passwordMin8bit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:03:10Z DEBUG uidNumber 2019-01-17T11:03:10Z DEBUG nsslapd-validate-cert: 2019-01-17T11:03:10Z DEBUG warn 2019-01-17T11:03:10Z DEBUG passwordMinCategories: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG passwordMinLowers: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordAdminDN: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordMinSpecials: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-lastmod: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:03:10Z DEBUG 40 2019-01-17T11:03:10Z DEBUG passwordMaxRepeats: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:03:10Z DEBUG -1 2019-01-17T11:03:10Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG nsslapd-result-tweak: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG passwordUnlock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-schemacheck: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-maxbersize: 2019-01-17T11:03:10Z DEBUG 209715200 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:03:10Z DEBUG dc=example,dc=com 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-localssf: 2019-01-17T11:03:10Z DEBUG 71 2019-01-17T11:03:10Z DEBUG nsslapd-sizelimit: 2019-01-17T11:03:10Z DEBUG 2000 2019-01-17T11:03:10Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG passwordLockoutDuration: 2019-01-17T11:03:10Z DEBUG 3600 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-port: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:03:10Z DEBUG cn=schema 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG cn=monitor 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-rootpw: 2019-01-17T11:03:10Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:03:10Z DEBUG 300000 2019-01-17T11:03:10Z DEBUG nsslapd-workingdir: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-rundir: 2019-01-17T11:03:10Z DEBUG /var/run/dirsrv 2019-01-17T11:03:10Z DEBUG nsslapd-schemareplace: 2019-01-17T11:03:10Z DEBUG replication-only 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:03:10Z DEBUG 16384 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:03:10Z DEBUG 10000 2019-01-17T11:03:10Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinDigits: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG passwordStorageScheme: 2019-01-17T11:03:10Z DEBUG SSHA512 2019-01-17T11:03:10Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-betype: 2019-01-17T11:03:10Z DEBUG ldbm database 2019-01-17T11:03:10Z DEBUG nsslapd-nagle: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-referralmode: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:03:10Z DEBUG 64 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 500 2019-01-17T11:03:10Z DEBUG passwordMinAlphas: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-readonly: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordLegacyPolicy: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:03:10Z DEBUG allowed 2019-01-17T11:03:10Z DEBUG passwordMinUppers: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-plugin: 2019-01-17T11:03:10Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:03:10Z DEBUG 20971520 2019-01-17T11:03:10Z DEBUG nsslapd-timelimit: 2019-01-17T11:03:10Z DEBUG 3600 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinTokenLength: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordMinAge: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:03:10Z DEBUG 60 2019-01-17T11:03:10Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:03:10Z DEBUG 1024 2019-01-17T11:03:10Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordInHistory: 2019-01-17T11:03:10Z DEBUG 6 2019-01-17T11:03:10Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-conntablesize: 2019-01-17T11:03:10Z DEBUG 16384 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-saslpath: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG passwordMaxAge: 2019-01-17T11:03:10Z DEBUG 8640000 2019-01-17T11:03:10Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:03:10Z DEBUG gidNumber 2019-01-17T11:03:10Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG day 2019-01-17T11:03:10Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-csnlogging: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-tmpdir: 2019-01-17T11:03:10Z DEBUG /tmp 2019-01-17T11:03:10Z DEBUG passwordResetFailureCount: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-counters: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-svrtab: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-minssf: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-schemadir: 2019-01-17T11:03:10Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:03:10Z DEBUG nsslapd-localuser: 2019-01-17T11:03:10Z DEBUG dirsrv 2019-01-17T11:03:10Z DEBUG nsslapd-security: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordChange: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-port 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:03:10Z DEBUG passwordMaxFailure: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:03:10Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:03:10Z DEBUG 128 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:03:10Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-rootdn: 2019-01-17T11:03:10Z DEBUG cn=Directory Manager 2019-01-17T11:03:10Z DEBUG nsslapd-ldifdir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:03:10Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordMustChange: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordExp: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-logging-backend: 2019-01-17T11:03:10Z DEBUG dirsrv-log 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:10Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:03:10Z DEBUG cn=Directory Manager 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinLength: 2019-01-17T11:03:10Z DEBUG 8 2019-01-17T11:03:10Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-idletimeout: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-securePort: 2019-01-17T11:03:10Z DEBUG 636 2019-01-17T11:03:10Z DEBUG nsslapd-snmp-index: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG config 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapdConfig 2019-01-17T11:03:10Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordSendExpiringTime: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-hash-filters: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:03:10Z DEBUG next 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-listenhost: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordCheckSyntax: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordGraceLimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG passwordWarning: 2019-01-17T11:03:10Z DEBUG 86400 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-instancedir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-config: 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-versionstring: 2019-01-17T11:03:10Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:03:10Z DEBUG 256 2019-01-17T11:03:10Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:03:10Z DEBUG SSHA512 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordLockout: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-lockdir: 2019-01-17T11:03:10Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-certdir: 2019-01-17T11:03:10Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 10 2019-01-17T11:03:10Z DEBUG nsslapd-backendconfig: 2019-01-17T11:03:10Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-threadnumber: 2019-01-17T11:03:10Z DEBUG 24 2019-01-17T11:03:10Z DEBUG nsslapd-schemamod: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-localhost: 2019-01-17T11:03:10Z DEBUG centos75.local 2019-01-17T11:03:10Z DEBUG nsslapd-bakdir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:03:10Z DEBUG passwordMin8bit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:03:10Z DEBUG uidNumber 2019-01-17T11:03:10Z DEBUG nsslapd-validate-cert: 2019-01-17T11:03:10Z DEBUG warn 2019-01-17T11:03:10Z DEBUG passwordMinCategories: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG passwordMinLowers: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordAdminDN: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordMinSpecials: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-lastmod: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:03:10Z DEBUG 40 2019-01-17T11:03:10Z DEBUG passwordMaxRepeats: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:03:10Z DEBUG -1 2019-01-17T11:03:10Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG nsslapd-result-tweak: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG passwordUnlock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-schemacheck: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-maxbersize: 2019-01-17T11:03:10Z DEBUG 209715200 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:03:10Z DEBUG dc=example,dc=com 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-localssf: 2019-01-17T11:03:10Z DEBUG 71 2019-01-17T11:03:10Z DEBUG nsslapd-sizelimit: 2019-01-17T11:03:10Z DEBUG 2000 2019-01-17T11:03:10Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG passwordLockoutDuration: 2019-01-17T11:03:10Z DEBUG 3600 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-port: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:03:10Z DEBUG cn=schema 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG cn=monitor 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-rootpw: 2019-01-17T11:03:10Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:03:10Z DEBUG 300000 2019-01-17T11:03:10Z DEBUG nsslapd-workingdir: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-rundir: 2019-01-17T11:03:10Z DEBUG /var/run/dirsrv 2019-01-17T11:03:10Z DEBUG nsslapd-schemareplace: 2019-01-17T11:03:10Z DEBUG replication-only 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:03:10Z DEBUG 16384 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:03:10Z DEBUG 10000 2019-01-17T11:03:10Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinDigits: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG passwordStorageScheme: 2019-01-17T11:03:10Z DEBUG SSHA512 2019-01-17T11:03:10Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG only: set nsslapd-minssf-exclude-rootdse to 'on', current value [u'on'] 2019-01-17T11:03:10Z DEBUG only: updated value [u'on'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-betype: 2019-01-17T11:03:10Z DEBUG ldbm database 2019-01-17T11:03:10Z DEBUG nsslapd-nagle: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-referralmode: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:03:10Z DEBUG 64 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 500 2019-01-17T11:03:10Z DEBUG passwordMinAlphas: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-readonly: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordLegacyPolicy: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:03:10Z DEBUG allowed 2019-01-17T11:03:10Z DEBUG passwordMinUppers: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-plugin: 2019-01-17T11:03:10Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:03:10Z DEBUG 20971520 2019-01-17T11:03:10Z DEBUG nsslapd-timelimit: 2019-01-17T11:03:10Z DEBUG 3600 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinTokenLength: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordMinAge: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:03:10Z DEBUG 60 2019-01-17T11:03:10Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:03:10Z DEBUG 1024 2019-01-17T11:03:10Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordInHistory: 2019-01-17T11:03:10Z DEBUG 6 2019-01-17T11:03:10Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-conntablesize: 2019-01-17T11:03:10Z DEBUG 16384 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-saslpath: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG passwordMaxAge: 2019-01-17T11:03:10Z DEBUG 8640000 2019-01-17T11:03:10Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:03:10Z DEBUG gidNumber 2019-01-17T11:03:10Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG day 2019-01-17T11:03:10Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-csnlogging: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-tmpdir: 2019-01-17T11:03:10Z DEBUG /tmp 2019-01-17T11:03:10Z DEBUG passwordResetFailureCount: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-counters: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-svrtab: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-minssf: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-schemadir: 2019-01-17T11:03:10Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:03:10Z DEBUG nsslapd-localuser: 2019-01-17T11:03:10Z DEBUG dirsrv 2019-01-17T11:03:10Z DEBUG nsslapd-security: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordChange: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-port 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:03:10Z DEBUG passwordMaxFailure: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:03:10Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:03:10Z DEBUG 128 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:03:10Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-rootdn: 2019-01-17T11:03:10Z DEBUG cn=Directory Manager 2019-01-17T11:03:10Z DEBUG nsslapd-ldifdir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:03:10Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordMustChange: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordExp: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-logging-backend: 2019-01-17T11:03:10Z DEBUG dirsrv-log 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:10Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:03:10Z DEBUG cn=Directory Manager 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinLength: 2019-01-17T11:03:10Z DEBUG 8 2019-01-17T11:03:10Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-idletimeout: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-securePort: 2019-01-17T11:03:10Z DEBUG 636 2019-01-17T11:03:10Z DEBUG nsslapd-snmp-index: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG config 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapdConfig 2019-01-17T11:03:10Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordSendExpiringTime: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-hash-filters: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:03:10Z DEBUG next 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-listenhost: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordCheckSyntax: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordGraceLimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG passwordWarning: 2019-01-17T11:03:10Z DEBUG 86400 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-instancedir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-config: 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-versionstring: 2019-01-17T11:03:10Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:03:10Z DEBUG 256 2019-01-17T11:03:10Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:03:10Z DEBUG SSHA512 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordLockout: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-lockdir: 2019-01-17T11:03:10Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-certdir: 2019-01-17T11:03:10Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 10 2019-01-17T11:03:10Z DEBUG nsslapd-backendconfig: 2019-01-17T11:03:10Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-threadnumber: 2019-01-17T11:03:10Z DEBUG 24 2019-01-17T11:03:10Z DEBUG nsslapd-schemamod: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-localhost: 2019-01-17T11:03:10Z DEBUG centos75.local 2019-01-17T11:03:10Z DEBUG nsslapd-bakdir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:03:10Z DEBUG passwordMin8bit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:03:10Z DEBUG uidNumber 2019-01-17T11:03:10Z DEBUG nsslapd-validate-cert: 2019-01-17T11:03:10Z DEBUG warn 2019-01-17T11:03:10Z DEBUG passwordMinCategories: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG passwordMinLowers: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordAdminDN: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordMinSpecials: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-lastmod: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:03:10Z DEBUG 40 2019-01-17T11:03:10Z DEBUG passwordMaxRepeats: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:03:10Z DEBUG -1 2019-01-17T11:03:10Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG nsslapd-result-tweak: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG passwordUnlock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-schemacheck: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-maxbersize: 2019-01-17T11:03:10Z DEBUG 209715200 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:03:10Z DEBUG dc=example,dc=com 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-localssf: 2019-01-17T11:03:10Z DEBUG 71 2019-01-17T11:03:10Z DEBUG nsslapd-sizelimit: 2019-01-17T11:03:10Z DEBUG 2000 2019-01-17T11:03:10Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG passwordLockoutDuration: 2019-01-17T11:03:10Z DEBUG 3600 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-port: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:03:10Z DEBUG cn=schema 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG cn=monitor 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-rootpw: 2019-01-17T11:03:10Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:03:10Z DEBUG 300000 2019-01-17T11:03:10Z DEBUG nsslapd-workingdir: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-rundir: 2019-01-17T11:03:10Z DEBUG /var/run/dirsrv 2019-01-17T11:03:10Z DEBUG nsslapd-schemareplace: 2019-01-17T11:03:10Z DEBUG replication-only 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:03:10Z DEBUG 16384 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:03:10Z DEBUG 10000 2019-01-17T11:03:10Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinDigits: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG passwordStorageScheme: 2019-01-17T11:03:10Z DEBUG SSHA512 2019-01-17T11:03:10Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=ipa-winsync,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=ipa-winsync,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG ipa-winsync 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG ipawinsynchomedirattr: 2019-01-17T11:03:10Z DEBUG ipaHomesRootDir 2019-01-17T11:03:10Z DEBUG ipawinsyncnewuserocattr: 2019-01-17T11:03:10Z DEBUG ipauserobjectclasses 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libipa_winsync 2019-01-17T11:03:10Z DEBUG ipawinsyncuserflatten: 2019-01-17T11:03:10Z DEBUG true 2019-01-17T11:03:10Z DEBUG ipawinsyncdefaultgroupfilter: 2019-01-17T11:03:10Z DEBUG (gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames) 2019-01-17T11:03:10Z DEBUG ipawinsyncforcesync: 2019-01-17T11:03:10Z DEBUG true 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG FreeIPA/1.0 2019-01-17T11:03:10Z DEBUG ipawinsyncrealmattr: 2019-01-17T11:03:10Z DEBUG cn 2019-01-17T11:03:10Z DEBUG ipawinsyncacctdisable: 2019-01-17T11:03:10Z DEBUG both 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG ipa_winsync_plugin_init 2019-01-17T11:03:10Z DEBUG ipawinsyncnewentryfilter: 2019-01-17T11:03:10Z DEBUG (cn=ipaConfig) 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG FreeIPA project 2019-01-17T11:03:10Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:03:10Z DEBUG 60 2019-01-17T11:03:10Z DEBUG ipawinsyncdefaultgroupattr: 2019-01-17T11:03:10Z DEBUG ipaDefaultPrimaryGroup 2019-01-17T11:03:10Z DEBUG ipawinsyncrealmfilter: 2019-01-17T11:03:10Z DEBUG (objectclass=krbRealmContainer) 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG preoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG ipa winsync plugin 2019-01-17T11:03:10Z DEBUG ipawinsyncloginshellattr: 2019-01-17T11:03:10Z DEBUG ipaDefaultLoginShell 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG ipa-winsync-plugin 2019-01-17T11:03:10Z DEBUG ipawinsyncuserattr: 2019-01-17T11:03:10Z DEBUG uidNumber -1 2019-01-17T11:03:10Z DEBUG gidNumber -1 2019-01-17T11:03:10Z DEBUG only: set nsslapd-pluginPrecedence to '60', current value [u'60'] 2019-01-17T11:03:10Z DEBUG only: updated value [u'60'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=ipa-winsync,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG ipa-winsync 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG ipawinsynchomedirattr: 2019-01-17T11:03:10Z DEBUG ipaHomesRootDir 2019-01-17T11:03:10Z DEBUG ipawinsyncnewuserocattr: 2019-01-17T11:03:10Z DEBUG ipauserobjectclasses 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libipa_winsync 2019-01-17T11:03:10Z DEBUG ipawinsyncuserflatten: 2019-01-17T11:03:10Z DEBUG true 2019-01-17T11:03:10Z DEBUG ipawinsyncdefaultgroupfilter: 2019-01-17T11:03:10Z DEBUG (gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames) 2019-01-17T11:03:10Z DEBUG ipawinsyncforcesync: 2019-01-17T11:03:10Z DEBUG true 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG FreeIPA/1.0 2019-01-17T11:03:10Z DEBUG ipawinsyncrealmattr: 2019-01-17T11:03:10Z DEBUG cn 2019-01-17T11:03:10Z DEBUG ipawinsyncacctdisable: 2019-01-17T11:03:10Z DEBUG both 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG ipa_winsync_plugin_init 2019-01-17T11:03:10Z DEBUG ipawinsyncnewentryfilter: 2019-01-17T11:03:10Z DEBUG (cn=ipaConfig) 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG FreeIPA project 2019-01-17T11:03:10Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:03:10Z DEBUG 60 2019-01-17T11:03:10Z DEBUG ipawinsyncdefaultgroupattr: 2019-01-17T11:03:10Z DEBUG ipaDefaultPrimaryGroup 2019-01-17T11:03:10Z DEBUG ipawinsyncrealmfilter: 2019-01-17T11:03:10Z DEBUG (objectclass=krbRealmContainer) 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG preoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG ipa winsync plugin 2019-01-17T11:03:10Z DEBUG ipawinsyncloginshellattr: 2019-01-17T11:03:10Z DEBUG ipaDefaultLoginShell 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG ipa-winsync-plugin 2019-01-17T11:03:10Z DEBUG ipawinsyncuserattr: 2019-01-17T11:03:10Z DEBUG uidNumber -1 2019-01-17T11:03:10Z DEBUG gidNumber -1 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-betype: 2019-01-17T11:03:10Z DEBUG ldbm database 2019-01-17T11:03:10Z DEBUG nsslapd-nagle: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-referralmode: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:03:10Z DEBUG 64 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 500 2019-01-17T11:03:10Z DEBUG passwordMinAlphas: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-readonly: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordLegacyPolicy: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:03:10Z DEBUG allowed 2019-01-17T11:03:10Z DEBUG passwordMinUppers: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-plugin: 2019-01-17T11:03:10Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:03:10Z DEBUG 20971520 2019-01-17T11:03:10Z DEBUG nsslapd-timelimit: 2019-01-17T11:03:10Z DEBUG 3600 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinTokenLength: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordMinAge: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:03:10Z DEBUG 60 2019-01-17T11:03:10Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:03:10Z DEBUG 1024 2019-01-17T11:03:10Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordInHistory: 2019-01-17T11:03:10Z DEBUG 6 2019-01-17T11:03:10Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-conntablesize: 2019-01-17T11:03:10Z DEBUG 16384 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-saslpath: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG passwordMaxAge: 2019-01-17T11:03:10Z DEBUG 8640000 2019-01-17T11:03:10Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:03:10Z DEBUG gidNumber 2019-01-17T11:03:10Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG day 2019-01-17T11:03:10Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-csnlogging: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-tmpdir: 2019-01-17T11:03:10Z DEBUG /tmp 2019-01-17T11:03:10Z DEBUG passwordResetFailureCount: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-counters: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-svrtab: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-minssf: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-schemadir: 2019-01-17T11:03:10Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:03:10Z DEBUG nsslapd-localuser: 2019-01-17T11:03:10Z DEBUG dirsrv 2019-01-17T11:03:10Z DEBUG nsslapd-security: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordChange: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-port 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:03:10Z DEBUG passwordMaxFailure: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:03:10Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:03:10Z DEBUG 128 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:03:10Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-rootdn: 2019-01-17T11:03:10Z DEBUG cn=Directory Manager 2019-01-17T11:03:10Z DEBUG nsslapd-ldifdir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:03:10Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordMustChange: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordExp: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-logging-backend: 2019-01-17T11:03:10Z DEBUG dirsrv-log 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:10Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:03:10Z DEBUG cn=Directory Manager 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinLength: 2019-01-17T11:03:10Z DEBUG 8 2019-01-17T11:03:10Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-idletimeout: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-securePort: 2019-01-17T11:03:10Z DEBUG 636 2019-01-17T11:03:10Z DEBUG nsslapd-snmp-index: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG config 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapdConfig 2019-01-17T11:03:10Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordSendExpiringTime: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-hash-filters: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:03:10Z DEBUG next 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-listenhost: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordCheckSyntax: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordGraceLimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG passwordWarning: 2019-01-17T11:03:10Z DEBUG 86400 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-instancedir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-config: 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-versionstring: 2019-01-17T11:03:10Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:03:10Z DEBUG 256 2019-01-17T11:03:10Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:03:10Z DEBUG SSHA512 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordLockout: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-lockdir: 2019-01-17T11:03:10Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-certdir: 2019-01-17T11:03:10Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 10 2019-01-17T11:03:10Z DEBUG nsslapd-backendconfig: 2019-01-17T11:03:10Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-threadnumber: 2019-01-17T11:03:10Z DEBUG 24 2019-01-17T11:03:10Z DEBUG nsslapd-schemamod: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-localhost: 2019-01-17T11:03:10Z DEBUG centos75.local 2019-01-17T11:03:10Z DEBUG nsslapd-bakdir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:03:10Z DEBUG passwordMin8bit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:03:10Z DEBUG uidNumber 2019-01-17T11:03:10Z DEBUG nsslapd-validate-cert: 2019-01-17T11:03:10Z DEBUG warn 2019-01-17T11:03:10Z DEBUG passwordMinCategories: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG passwordMinLowers: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordAdminDN: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordMinSpecials: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-lastmod: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:03:10Z DEBUG 40 2019-01-17T11:03:10Z DEBUG passwordMaxRepeats: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:03:10Z DEBUG -1 2019-01-17T11:03:10Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG nsslapd-result-tweak: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG passwordUnlock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-schemacheck: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-maxbersize: 2019-01-17T11:03:10Z DEBUG 209715200 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:03:10Z DEBUG dc=example,dc=com 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-localssf: 2019-01-17T11:03:10Z DEBUG 71 2019-01-17T11:03:10Z DEBUG nsslapd-sizelimit: 2019-01-17T11:03:10Z DEBUG 2000 2019-01-17T11:03:10Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG passwordLockoutDuration: 2019-01-17T11:03:10Z DEBUG 3600 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-port: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:03:10Z DEBUG cn=schema 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG cn=monitor 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-rootpw: 2019-01-17T11:03:10Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:03:10Z DEBUG 300000 2019-01-17T11:03:10Z DEBUG nsslapd-workingdir: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-rundir: 2019-01-17T11:03:10Z DEBUG /var/run/dirsrv 2019-01-17T11:03:10Z DEBUG nsslapd-schemareplace: 2019-01-17T11:03:10Z DEBUG replication-only 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:03:10Z DEBUG 16384 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:03:10Z DEBUG 10000 2019-01-17T11:03:10Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinDigits: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG passwordStorageScheme: 2019-01-17T11:03:10Z DEBUG SSHA512 2019-01-17T11:03:10Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG only: set nsslapd-sasl-mapping-fallback to 'on', current value [u'on'] 2019-01-17T11:03:10Z DEBUG only: updated value [u'on'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-betype: 2019-01-17T11:03:10Z DEBUG ldbm database 2019-01-17T11:03:10Z DEBUG nsslapd-nagle: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-referralmode: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:03:10Z DEBUG 64 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 500 2019-01-17T11:03:10Z DEBUG passwordMinAlphas: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-readonly: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordLegacyPolicy: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:03:10Z DEBUG allowed 2019-01-17T11:03:10Z DEBUG passwordMinUppers: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-plugin: 2019-01-17T11:03:10Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:03:10Z DEBUG 20971520 2019-01-17T11:03:10Z DEBUG nsslapd-timelimit: 2019-01-17T11:03:10Z DEBUG 3600 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinTokenLength: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordMinAge: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:03:10Z DEBUG 60 2019-01-17T11:03:10Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:03:10Z DEBUG 1024 2019-01-17T11:03:10Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordInHistory: 2019-01-17T11:03:10Z DEBUG 6 2019-01-17T11:03:10Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-conntablesize: 2019-01-17T11:03:10Z DEBUG 16384 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-saslpath: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG passwordMaxAge: 2019-01-17T11:03:10Z DEBUG 8640000 2019-01-17T11:03:10Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:03:10Z DEBUG gidNumber 2019-01-17T11:03:10Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG day 2019-01-17T11:03:10Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-csnlogging: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-tmpdir: 2019-01-17T11:03:10Z DEBUG /tmp 2019-01-17T11:03:10Z DEBUG passwordResetFailureCount: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-counters: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-svrtab: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-minssf: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-schemadir: 2019-01-17T11:03:10Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:03:10Z DEBUG nsslapd-localuser: 2019-01-17T11:03:10Z DEBUG dirsrv 2019-01-17T11:03:10Z DEBUG nsslapd-security: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordChange: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-port 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:03:10Z DEBUG passwordMaxFailure: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:03:10Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:03:10Z DEBUG 128 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:03:10Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-rootdn: 2019-01-17T11:03:10Z DEBUG cn=Directory Manager 2019-01-17T11:03:10Z DEBUG nsslapd-ldifdir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:03:10Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordMustChange: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordExp: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-logging-backend: 2019-01-17T11:03:10Z DEBUG dirsrv-log 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:10Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:03:10Z DEBUG cn=Directory Manager 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinLength: 2019-01-17T11:03:10Z DEBUG 8 2019-01-17T11:03:10Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-idletimeout: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-securePort: 2019-01-17T11:03:10Z DEBUG 636 2019-01-17T11:03:10Z DEBUG nsslapd-snmp-index: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG config 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapdConfig 2019-01-17T11:03:10Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordSendExpiringTime: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-hash-filters: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:03:10Z DEBUG next 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-listenhost: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordCheckSyntax: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordGraceLimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG passwordWarning: 2019-01-17T11:03:10Z DEBUG 86400 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-instancedir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-config: 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-versionstring: 2019-01-17T11:03:10Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:03:10Z DEBUG 256 2019-01-17T11:03:10Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:03:10Z DEBUG SSHA512 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordLockout: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-lockdir: 2019-01-17T11:03:10Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-certdir: 2019-01-17T11:03:10Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 10 2019-01-17T11:03:10Z DEBUG nsslapd-backendconfig: 2019-01-17T11:03:10Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-threadnumber: 2019-01-17T11:03:10Z DEBUG 24 2019-01-17T11:03:10Z DEBUG nsslapd-schemamod: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-localhost: 2019-01-17T11:03:10Z DEBUG centos75.local 2019-01-17T11:03:10Z DEBUG nsslapd-bakdir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:03:10Z DEBUG passwordMin8bit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:03:10Z DEBUG uidNumber 2019-01-17T11:03:10Z DEBUG nsslapd-validate-cert: 2019-01-17T11:03:10Z DEBUG warn 2019-01-17T11:03:10Z DEBUG passwordMinCategories: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG passwordMinLowers: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordAdminDN: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordMinSpecials: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-lastmod: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:03:10Z DEBUG 40 2019-01-17T11:03:10Z DEBUG passwordMaxRepeats: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:03:10Z DEBUG -1 2019-01-17T11:03:10Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG nsslapd-result-tweak: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG passwordUnlock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-schemacheck: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-maxbersize: 2019-01-17T11:03:10Z DEBUG 209715200 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:03:10Z DEBUG dc=example,dc=com 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-localssf: 2019-01-17T11:03:10Z DEBUG 71 2019-01-17T11:03:10Z DEBUG nsslapd-sizelimit: 2019-01-17T11:03:10Z DEBUG 2000 2019-01-17T11:03:10Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG passwordLockoutDuration: 2019-01-17T11:03:10Z DEBUG 3600 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-port: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:03:10Z DEBUG cn=schema 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG cn=monitor 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-rootpw: 2019-01-17T11:03:10Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:03:10Z DEBUG 300000 2019-01-17T11:03:10Z DEBUG nsslapd-workingdir: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-rundir: 2019-01-17T11:03:10Z DEBUG /var/run/dirsrv 2019-01-17T11:03:10Z DEBUG nsslapd-schemareplace: 2019-01-17T11:03:10Z DEBUG replication-only 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:03:10Z DEBUG 16384 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:03:10Z DEBUG 10000 2019-01-17T11:03:10Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinDigits: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG passwordStorageScheme: 2019-01-17T11:03:10Z DEBUG SSHA512 2019-01-17T11:03:10Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=Full Principal,cn=mapping,cn=sasl,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=Full Principal,cn=mapping,cn=sasl,cn=config 2019-01-17T11:03:10Z DEBUG nsSaslMapPriority: 2019-01-17T11:03:10Z DEBUG 10 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG Full Principal 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSaslMapping 2019-01-17T11:03:10Z DEBUG nsSaslMapRegexString: 2019-01-17T11:03:10Z DEBUG \(.*\)@\(.*\) 2019-01-17T11:03:10Z DEBUG nsSaslMapBaseDNTemplate: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsSaslMapFilterTemplate: 2019-01-17T11:03:10Z DEBUG (krbPrincipalName=\1@\2) 2019-01-17T11:03:10Z DEBUG addifnew: '10' to nsSaslMapPriority, current value [u'10'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=Full Principal,cn=mapping,cn=sasl,cn=config 2019-01-17T11:03:10Z DEBUG nsSaslMapPriority: 2019-01-17T11:03:10Z DEBUG 10 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG Full Principal 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSaslMapping 2019-01-17T11:03:10Z DEBUG nsSaslMapRegexString: 2019-01-17T11:03:10Z DEBUG \(.*\)@\(.*\) 2019-01-17T11:03:10Z DEBUG nsSaslMapBaseDNTemplate: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsSaslMapFilterTemplate: 2019-01-17T11:03:10Z DEBUG (krbPrincipalName=\1@\2) 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=Name Only,cn=mapping,cn=sasl,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=Name Only,cn=mapping,cn=sasl,cn=config 2019-01-17T11:03:10Z DEBUG nsSaslMapPriority: 2019-01-17T11:03:10Z DEBUG 10 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG Name Only 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSaslMapping 2019-01-17T11:03:10Z DEBUG nsSaslMapRegexString: 2019-01-17T11:03:10Z DEBUG ^[^:@]+$ 2019-01-17T11:03:10Z DEBUG nsSaslMapBaseDNTemplate: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsSaslMapFilterTemplate: 2019-01-17T11:03:10Z DEBUG (krbPrincipalName=&@LOCAL) 2019-01-17T11:03:10Z DEBUG addifnew: '10' to nsSaslMapPriority, current value [u'10'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=Name Only,cn=mapping,cn=sasl,cn=config 2019-01-17T11:03:10Z DEBUG nsSaslMapPriority: 2019-01-17T11:03:10Z DEBUG 10 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG Name Only 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSaslMapping 2019-01-17T11:03:10Z DEBUG nsSaslMapRegexString: 2019-01-17T11:03:10Z DEBUG ^[^:@]+$ 2019-01-17T11:03:10Z DEBUG nsSaslMapBaseDNTemplate: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsSaslMapFilterTemplate: 2019-01-17T11:03:10Z DEBUG (krbPrincipalName=&@LOCAL) 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-betype: 2019-01-17T11:03:10Z DEBUG ldbm database 2019-01-17T11:03:10Z DEBUG nsslapd-nagle: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-referralmode: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:03:10Z DEBUG 64 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 500 2019-01-17T11:03:10Z DEBUG passwordMinAlphas: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-readonly: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordLegacyPolicy: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:03:10Z DEBUG allowed 2019-01-17T11:03:10Z DEBUG passwordMinUppers: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-plugin: 2019-01-17T11:03:10Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:03:10Z DEBUG 20971520 2019-01-17T11:03:10Z DEBUG nsslapd-timelimit: 2019-01-17T11:03:10Z DEBUG 3600 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinTokenLength: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordMinAge: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:03:10Z DEBUG 60 2019-01-17T11:03:10Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:03:10Z DEBUG 1024 2019-01-17T11:03:10Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordInHistory: 2019-01-17T11:03:10Z DEBUG 6 2019-01-17T11:03:10Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-conntablesize: 2019-01-17T11:03:10Z DEBUG 16384 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-saslpath: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG passwordMaxAge: 2019-01-17T11:03:10Z DEBUG 8640000 2019-01-17T11:03:10Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:03:10Z DEBUG gidNumber 2019-01-17T11:03:10Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG day 2019-01-17T11:03:10Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-csnlogging: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-tmpdir: 2019-01-17T11:03:10Z DEBUG /tmp 2019-01-17T11:03:10Z DEBUG passwordResetFailureCount: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-counters: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-svrtab: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-minssf: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-schemadir: 2019-01-17T11:03:10Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:03:10Z DEBUG nsslapd-localuser: 2019-01-17T11:03:10Z DEBUG dirsrv 2019-01-17T11:03:10Z DEBUG nsslapd-security: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordChange: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-port 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:03:10Z DEBUG passwordMaxFailure: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:03:10Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:03:10Z DEBUG 128 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:03:10Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-rootdn: 2019-01-17T11:03:10Z DEBUG cn=Directory Manager 2019-01-17T11:03:10Z DEBUG nsslapd-ldifdir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:03:10Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordMustChange: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordExp: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-logging-backend: 2019-01-17T11:03:10Z DEBUG dirsrv-log 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:10Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:03:10Z DEBUG cn=Directory Manager 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinLength: 2019-01-17T11:03:10Z DEBUG 8 2019-01-17T11:03:10Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-idletimeout: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-securePort: 2019-01-17T11:03:10Z DEBUG 636 2019-01-17T11:03:10Z DEBUG nsslapd-snmp-index: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG config 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapdConfig 2019-01-17T11:03:10Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordSendExpiringTime: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-hash-filters: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:03:10Z DEBUG next 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-listenhost: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordCheckSyntax: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordGraceLimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG passwordWarning: 2019-01-17T11:03:10Z DEBUG 86400 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-instancedir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-config: 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-versionstring: 2019-01-17T11:03:10Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:03:10Z DEBUG 256 2019-01-17T11:03:10Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:03:10Z DEBUG SSHA512 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordLockout: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-lockdir: 2019-01-17T11:03:10Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-certdir: 2019-01-17T11:03:10Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 10 2019-01-17T11:03:10Z DEBUG nsslapd-backendconfig: 2019-01-17T11:03:10Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-threadnumber: 2019-01-17T11:03:10Z DEBUG 24 2019-01-17T11:03:10Z DEBUG nsslapd-schemamod: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-localhost: 2019-01-17T11:03:10Z DEBUG centos75.local 2019-01-17T11:03:10Z DEBUG nsslapd-bakdir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:03:10Z DEBUG passwordMin8bit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:03:10Z DEBUG uidNumber 2019-01-17T11:03:10Z DEBUG nsslapd-validate-cert: 2019-01-17T11:03:10Z DEBUG warn 2019-01-17T11:03:10Z DEBUG passwordMinCategories: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG passwordMinLowers: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordAdminDN: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordMinSpecials: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-lastmod: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:03:10Z DEBUG 40 2019-01-17T11:03:10Z DEBUG passwordMaxRepeats: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:03:10Z DEBUG -1 2019-01-17T11:03:10Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG nsslapd-result-tweak: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG passwordUnlock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-schemacheck: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-maxbersize: 2019-01-17T11:03:10Z DEBUG 209715200 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:03:10Z DEBUG dc=example,dc=com 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-localssf: 2019-01-17T11:03:10Z DEBUG 71 2019-01-17T11:03:10Z DEBUG nsslapd-sizelimit: 2019-01-17T11:03:10Z DEBUG 2000 2019-01-17T11:03:10Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG passwordLockoutDuration: 2019-01-17T11:03:10Z DEBUG 3600 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-port: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:03:10Z DEBUG cn=schema 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG cn=monitor 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-rootpw: 2019-01-17T11:03:10Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:03:10Z DEBUG 300000 2019-01-17T11:03:10Z DEBUG nsslapd-workingdir: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-rundir: 2019-01-17T11:03:10Z DEBUG /var/run/dirsrv 2019-01-17T11:03:10Z DEBUG nsslapd-schemareplace: 2019-01-17T11:03:10Z DEBUG replication-only 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:03:10Z DEBUG 16384 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:03:10Z DEBUG 10000 2019-01-17T11:03:10Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinDigits: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG passwordStorageScheme: 2019-01-17T11:03:10Z DEBUG SSHA512 2019-01-17T11:03:10Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG only: set nsslapd-allow-hashed-passwords to 'on', current value [u'on'] 2019-01-17T11:03:10Z DEBUG only: updated value [u'on'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-betype: 2019-01-17T11:03:10Z DEBUG ldbm database 2019-01-17T11:03:10Z DEBUG nsslapd-nagle: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-referralmode: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:03:10Z DEBUG 64 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 500 2019-01-17T11:03:10Z DEBUG passwordMinAlphas: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-readonly: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordLegacyPolicy: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:03:10Z DEBUG allowed 2019-01-17T11:03:10Z DEBUG passwordMinUppers: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-plugin: 2019-01-17T11:03:10Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:03:10Z DEBUG 20971520 2019-01-17T11:03:10Z DEBUG nsslapd-timelimit: 2019-01-17T11:03:10Z DEBUG 3600 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinTokenLength: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordMinAge: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:03:10Z DEBUG 60 2019-01-17T11:03:10Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:03:10Z DEBUG 1024 2019-01-17T11:03:10Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordInHistory: 2019-01-17T11:03:10Z DEBUG 6 2019-01-17T11:03:10Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-conntablesize: 2019-01-17T11:03:10Z DEBUG 16384 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-saslpath: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG passwordMaxAge: 2019-01-17T11:03:10Z DEBUG 8640000 2019-01-17T11:03:10Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:03:10Z DEBUG gidNumber 2019-01-17T11:03:10Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG day 2019-01-17T11:03:10Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-csnlogging: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-tmpdir: 2019-01-17T11:03:10Z DEBUG /tmp 2019-01-17T11:03:10Z DEBUG passwordResetFailureCount: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-counters: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-svrtab: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-minssf: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-schemadir: 2019-01-17T11:03:10Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:03:10Z DEBUG nsslapd-localuser: 2019-01-17T11:03:10Z DEBUG dirsrv 2019-01-17T11:03:10Z DEBUG nsslapd-security: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordChange: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-port 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:03:10Z DEBUG passwordMaxFailure: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:03:10Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:03:10Z DEBUG 128 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:03:10Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-rootdn: 2019-01-17T11:03:10Z DEBUG cn=Directory Manager 2019-01-17T11:03:10Z DEBUG nsslapd-ldifdir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:03:10Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordMustChange: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordExp: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-logging-backend: 2019-01-17T11:03:10Z DEBUG dirsrv-log 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:10Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:03:10Z DEBUG cn=Directory Manager 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinLength: 2019-01-17T11:03:10Z DEBUG 8 2019-01-17T11:03:10Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-idletimeout: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-securePort: 2019-01-17T11:03:10Z DEBUG 636 2019-01-17T11:03:10Z DEBUG nsslapd-snmp-index: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG config 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapdConfig 2019-01-17T11:03:10Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordSendExpiringTime: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-hash-filters: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:03:10Z DEBUG next 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-listenhost: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordCheckSyntax: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordGraceLimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG passwordWarning: 2019-01-17T11:03:10Z DEBUG 86400 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-instancedir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-config: 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-versionstring: 2019-01-17T11:03:10Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:03:10Z DEBUG 256 2019-01-17T11:03:10Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:03:10Z DEBUG SSHA512 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordLockout: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-lockdir: 2019-01-17T11:03:10Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-certdir: 2019-01-17T11:03:10Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 10 2019-01-17T11:03:10Z DEBUG nsslapd-backendconfig: 2019-01-17T11:03:10Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-threadnumber: 2019-01-17T11:03:10Z DEBUG 24 2019-01-17T11:03:10Z DEBUG nsslapd-schemamod: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-localhost: 2019-01-17T11:03:10Z DEBUG centos75.local 2019-01-17T11:03:10Z DEBUG nsslapd-bakdir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:03:10Z DEBUG passwordMin8bit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:03:10Z DEBUG uidNumber 2019-01-17T11:03:10Z DEBUG nsslapd-validate-cert: 2019-01-17T11:03:10Z DEBUG warn 2019-01-17T11:03:10Z DEBUG passwordMinCategories: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG passwordMinLowers: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordAdminDN: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordMinSpecials: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-lastmod: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:03:10Z DEBUG 40 2019-01-17T11:03:10Z DEBUG passwordMaxRepeats: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:03:10Z DEBUG -1 2019-01-17T11:03:10Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG nsslapd-result-tweak: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG passwordUnlock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-schemacheck: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-maxbersize: 2019-01-17T11:03:10Z DEBUG 209715200 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:03:10Z DEBUG dc=example,dc=com 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-localssf: 2019-01-17T11:03:10Z DEBUG 71 2019-01-17T11:03:10Z DEBUG nsslapd-sizelimit: 2019-01-17T11:03:10Z DEBUG 2000 2019-01-17T11:03:10Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG passwordLockoutDuration: 2019-01-17T11:03:10Z DEBUG 3600 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-port: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:03:10Z DEBUG cn=schema 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG cn=monitor 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-rootpw: 2019-01-17T11:03:10Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:03:10Z DEBUG 300000 2019-01-17T11:03:10Z DEBUG nsslapd-workingdir: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-rundir: 2019-01-17T11:03:10Z DEBUG /var/run/dirsrv 2019-01-17T11:03:10Z DEBUG nsslapd-schemareplace: 2019-01-17T11:03:10Z DEBUG replication-only 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:03:10Z DEBUG 16384 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:03:10Z DEBUG 10000 2019-01-17T11:03:10Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinDigits: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG passwordStorageScheme: 2019-01-17T11:03:10Z DEBUG SSHA512 2019-01-17T11:03:10Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-betype: 2019-01-17T11:03:10Z DEBUG ldbm database 2019-01-17T11:03:10Z DEBUG nsslapd-nagle: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-referralmode: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:03:10Z DEBUG 64 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 500 2019-01-17T11:03:10Z DEBUG passwordMinAlphas: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-readonly: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordLegacyPolicy: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:03:10Z DEBUG allowed 2019-01-17T11:03:10Z DEBUG passwordMinUppers: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-plugin: 2019-01-17T11:03:10Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:03:10Z DEBUG 20971520 2019-01-17T11:03:10Z DEBUG nsslapd-timelimit: 2019-01-17T11:03:10Z DEBUG 3600 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinTokenLength: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordMinAge: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:03:10Z DEBUG 60 2019-01-17T11:03:10Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:03:10Z DEBUG 1024 2019-01-17T11:03:10Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordInHistory: 2019-01-17T11:03:10Z DEBUG 6 2019-01-17T11:03:10Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-conntablesize: 2019-01-17T11:03:10Z DEBUG 16384 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-saslpath: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG passwordMaxAge: 2019-01-17T11:03:10Z DEBUG 8640000 2019-01-17T11:03:10Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:03:10Z DEBUG gidNumber 2019-01-17T11:03:10Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG day 2019-01-17T11:03:10Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-csnlogging: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-tmpdir: 2019-01-17T11:03:10Z DEBUG /tmp 2019-01-17T11:03:10Z DEBUG passwordResetFailureCount: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-counters: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-svrtab: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-minssf: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-schemadir: 2019-01-17T11:03:10Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:03:10Z DEBUG nsslapd-localuser: 2019-01-17T11:03:10Z DEBUG dirsrv 2019-01-17T11:03:10Z DEBUG nsslapd-security: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordChange: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-port 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:03:10Z DEBUG passwordMaxFailure: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:03:10Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:03:10Z DEBUG 128 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:03:10Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-rootdn: 2019-01-17T11:03:10Z DEBUG cn=Directory Manager 2019-01-17T11:03:10Z DEBUG nsslapd-ldifdir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:03:10Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordMustChange: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordExp: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-logging-backend: 2019-01-17T11:03:10Z DEBUG dirsrv-log 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:10Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:03:10Z DEBUG cn=Directory Manager 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinLength: 2019-01-17T11:03:10Z DEBUG 8 2019-01-17T11:03:10Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-idletimeout: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-securePort: 2019-01-17T11:03:10Z DEBUG 636 2019-01-17T11:03:10Z DEBUG nsslapd-snmp-index: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG config 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapdConfig 2019-01-17T11:03:10Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordSendExpiringTime: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-hash-filters: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:03:10Z DEBUG next 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-listenhost: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordCheckSyntax: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordGraceLimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG passwordWarning: 2019-01-17T11:03:10Z DEBUG 86400 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-instancedir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-config: 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-versionstring: 2019-01-17T11:03:10Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:03:10Z DEBUG 256 2019-01-17T11:03:10Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:03:10Z DEBUG SSHA512 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordLockout: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-lockdir: 2019-01-17T11:03:10Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-certdir: 2019-01-17T11:03:10Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 10 2019-01-17T11:03:10Z DEBUG nsslapd-backendconfig: 2019-01-17T11:03:10Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-threadnumber: 2019-01-17T11:03:10Z DEBUG 24 2019-01-17T11:03:10Z DEBUG nsslapd-schemamod: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-localhost: 2019-01-17T11:03:10Z DEBUG centos75.local 2019-01-17T11:03:10Z DEBUG nsslapd-bakdir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:03:10Z DEBUG passwordMin8bit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:03:10Z DEBUG uidNumber 2019-01-17T11:03:10Z DEBUG nsslapd-validate-cert: 2019-01-17T11:03:10Z DEBUG warn 2019-01-17T11:03:10Z DEBUG passwordMinCategories: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG passwordMinLowers: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordAdminDN: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordMinSpecials: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-lastmod: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:03:10Z DEBUG 40 2019-01-17T11:03:10Z DEBUG passwordMaxRepeats: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:03:10Z DEBUG -1 2019-01-17T11:03:10Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG nsslapd-result-tweak: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG passwordUnlock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-schemacheck: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-maxbersize: 2019-01-17T11:03:10Z DEBUG 209715200 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:03:10Z DEBUG dc=example,dc=com 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-localssf: 2019-01-17T11:03:10Z DEBUG 71 2019-01-17T11:03:10Z DEBUG nsslapd-sizelimit: 2019-01-17T11:03:10Z DEBUG 2000 2019-01-17T11:03:10Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG passwordLockoutDuration: 2019-01-17T11:03:10Z DEBUG 3600 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-port: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:03:10Z DEBUG cn=schema 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG cn=monitor 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-rootpw: 2019-01-17T11:03:10Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:03:10Z DEBUG 300000 2019-01-17T11:03:10Z DEBUG nsslapd-workingdir: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-rundir: 2019-01-17T11:03:10Z DEBUG /var/run/dirsrv 2019-01-17T11:03:10Z DEBUG nsslapd-schemareplace: 2019-01-17T11:03:10Z DEBUG replication-only 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:03:10Z DEBUG 16384 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:03:10Z DEBUG 10000 2019-01-17T11:03:10Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinDigits: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG passwordStorageScheme: 2019-01-17T11:03:10Z DEBUG SSHA512 2019-01-17T11:03:10Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG only: set nsslapd-ioblocktimeout to '10000', current value [u'10000'] 2019-01-17T11:03:10Z DEBUG only: updated value [u'10000'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-betype: 2019-01-17T11:03:10Z DEBUG ldbm database 2019-01-17T11:03:10Z DEBUG nsslapd-nagle: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-referralmode: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:03:10Z DEBUG 64 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 500 2019-01-17T11:03:10Z DEBUG passwordMinAlphas: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-readonly: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordLegacyPolicy: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:03:10Z DEBUG allowed 2019-01-17T11:03:10Z DEBUG passwordMinUppers: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-plugin: 2019-01-17T11:03:10Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:03:10Z DEBUG 20971520 2019-01-17T11:03:10Z DEBUG nsslapd-timelimit: 2019-01-17T11:03:10Z DEBUG 3600 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinTokenLength: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordMinAge: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:03:10Z DEBUG 60 2019-01-17T11:03:10Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:03:10Z DEBUG 1024 2019-01-17T11:03:10Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordInHistory: 2019-01-17T11:03:10Z DEBUG 6 2019-01-17T11:03:10Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-conntablesize: 2019-01-17T11:03:10Z DEBUG 16384 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-saslpath: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG passwordMaxAge: 2019-01-17T11:03:10Z DEBUG 8640000 2019-01-17T11:03:10Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:03:10Z DEBUG gidNumber 2019-01-17T11:03:10Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG day 2019-01-17T11:03:10Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-csnlogging: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-tmpdir: 2019-01-17T11:03:10Z DEBUG /tmp 2019-01-17T11:03:10Z DEBUG passwordResetFailureCount: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-counters: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-svrtab: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-minssf: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-schemadir: 2019-01-17T11:03:10Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:03:10Z DEBUG nsslapd-localuser: 2019-01-17T11:03:10Z DEBUG dirsrv 2019-01-17T11:03:10Z DEBUG nsslapd-security: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordChange: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-port 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:03:10Z DEBUG passwordMaxFailure: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:03:10Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:03:10Z DEBUG 128 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:03:10Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-rootdn: 2019-01-17T11:03:10Z DEBUG cn=Directory Manager 2019-01-17T11:03:10Z DEBUG nsslapd-ldifdir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:03:10Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordMustChange: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordExp: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-logging-backend: 2019-01-17T11:03:10Z DEBUG dirsrv-log 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:10Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:03:10Z DEBUG cn=Directory Manager 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinLength: 2019-01-17T11:03:10Z DEBUG 8 2019-01-17T11:03:10Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-idletimeout: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-securePort: 2019-01-17T11:03:10Z DEBUG 636 2019-01-17T11:03:10Z DEBUG nsslapd-snmp-index: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG config 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapdConfig 2019-01-17T11:03:10Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordSendExpiringTime: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-hash-filters: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:03:10Z DEBUG next 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-listenhost: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordCheckSyntax: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordGraceLimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG passwordWarning: 2019-01-17T11:03:10Z DEBUG 86400 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-instancedir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-config: 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-versionstring: 2019-01-17T11:03:10Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:03:10Z DEBUG 256 2019-01-17T11:03:10Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:03:10Z DEBUG SSHA512 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordLockout: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-lockdir: 2019-01-17T11:03:10Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-certdir: 2019-01-17T11:03:10Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 10 2019-01-17T11:03:10Z DEBUG nsslapd-backendconfig: 2019-01-17T11:03:10Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-threadnumber: 2019-01-17T11:03:10Z DEBUG 24 2019-01-17T11:03:10Z DEBUG nsslapd-schemamod: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-localhost: 2019-01-17T11:03:10Z DEBUG centos75.local 2019-01-17T11:03:10Z DEBUG nsslapd-bakdir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:03:10Z DEBUG passwordMin8bit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:03:10Z DEBUG uidNumber 2019-01-17T11:03:10Z DEBUG nsslapd-validate-cert: 2019-01-17T11:03:10Z DEBUG warn 2019-01-17T11:03:10Z DEBUG passwordMinCategories: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG passwordMinLowers: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordAdminDN: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordMinSpecials: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-lastmod: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:03:10Z DEBUG 40 2019-01-17T11:03:10Z DEBUG passwordMaxRepeats: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:03:10Z DEBUG -1 2019-01-17T11:03:10Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG nsslapd-result-tweak: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG passwordUnlock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-schemacheck: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-maxbersize: 2019-01-17T11:03:10Z DEBUG 209715200 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:03:10Z DEBUG dc=example,dc=com 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-localssf: 2019-01-17T11:03:10Z DEBUG 71 2019-01-17T11:03:10Z DEBUG nsslapd-sizelimit: 2019-01-17T11:03:10Z DEBUG 2000 2019-01-17T11:03:10Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG passwordLockoutDuration: 2019-01-17T11:03:10Z DEBUG 3600 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-port: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:03:10Z DEBUG cn=schema 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG cn=monitor 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-rootpw: 2019-01-17T11:03:10Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:03:10Z DEBUG 300000 2019-01-17T11:03:10Z DEBUG nsslapd-workingdir: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-rundir: 2019-01-17T11:03:10Z DEBUG /var/run/dirsrv 2019-01-17T11:03:10Z DEBUG nsslapd-schemareplace: 2019-01-17T11:03:10Z DEBUG replication-only 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:03:10Z DEBUG 16384 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:03:10Z DEBUG 10000 2019-01-17T11:03:10Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinDigits: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG passwordStorageScheme: 2019-01-17T11:03:10Z DEBUG SSHA512 2019-01-17T11:03:10Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Parsing update file '/usr/share/ipa/updates/10-enable-betxn.update' 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=7-bit check,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG NS7bitAttr 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG 7-bit check 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG NS7bitAttr_Init 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG Enforce 7-bit clean attribute values 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libattr-unique-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginarg0: 2019-01-17T11:03:10Z DEBUG uid 2019-01-17T11:03:10Z DEBUG nsslapd-pluginarg3: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-pluginarg2: 2019-01-17T11:03:10Z DEBUG , 2019-01-17T11:03:10Z DEBUG nsslapd-pluginarg1: 2019-01-17T11:03:10Z DEBUG mail 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG betxnpreoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value [u'betxnpreoperation'] 2019-01-17T11:03:10Z DEBUG only: updated value [u'betxnpreoperation'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG NS7bitAttr 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG 7-bit check 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG NS7bitAttr_Init 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG Enforce 7-bit clean attribute values 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libattr-unique-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginarg0: 2019-01-17T11:03:10Z DEBUG uid 2019-01-17T11:03:10Z DEBUG nsslapd-pluginarg3: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-pluginarg2: 2019-01-17T11:03:10Z DEBUG , 2019-01-17T11:03:10Z DEBUG nsslapd-pluginarg1: 2019-01-17T11:03:10Z DEBUG mail 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG betxnpreoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=attribute uniqueness,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=attribute uniqueness,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG uniqueness-attribute-name: 2019-01-17T11:03:10Z DEBUG uid 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG attribute uniqueness 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG uniqueness-across-all-subtrees: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libattr-unique-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG uniqueness-subtrees: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG betxnpreoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG NSUniqueAttr_Init 2019-01-17T11:03:10Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value [u'betxnpreoperation'] 2019-01-17T11:03:10Z DEBUG only: updated value [u'betxnpreoperation'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=attribute uniqueness,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG uniqueness-attribute-name: 2019-01-17T11:03:10Z DEBUG uid 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG attribute uniqueness 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG uniqueness-across-all-subtrees: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libattr-unique-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG uniqueness-subtrees: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG betxnpreoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG NSUniqueAttr_Init 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=Auto Membership Plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG Auto Membership 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG Auto Membership Plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG Auto Membership plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libautomember-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG nsslapd-pluginConfigArea: 2019-01-17T11:03:10Z DEBUG cn=automember,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG betxnpreoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG automember_init 2019-01-17T11:03:10Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value [u'betxnpreoperation'] 2019-01-17T11:03:10Z DEBUG only: updated value [u'betxnpreoperation'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG Auto Membership 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG Auto Membership Plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG Auto Membership plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libautomember-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG nsslapd-pluginConfigArea: 2019-01-17T11:03:10Z DEBUG cn=automember,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG betxnpreoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG automember_init 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=Linked Attributes,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=Linked Attributes,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG Linked Attributes 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG Linked Attributes 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG Linked Attributes plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG liblinkedattrs-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG betxnpreoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG linked_attrs_init 2019-01-17T11:03:10Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value [u'betxnpreoperation'] 2019-01-17T11:03:10Z DEBUG only: updated value [u'betxnpreoperation'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=Linked Attributes,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG Linked Attributes 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG Linked Attributes 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG Linked Attributes plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG liblinkedattrs-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG betxnpreoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG linked_attrs_init 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=Managed Entries,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG Managed Entries 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG Managed Entries 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG Managed Entries plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libmanagedentries-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG nsslapd-pluginConfigArea: 2019-01-17T11:03:10Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG betxnpreoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG mep_init 2019-01-17T11:03:10Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value [u'betxnpreoperation'] 2019-01-17T11:03:10Z DEBUG only: updated value [u'betxnpreoperation'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG Managed Entries 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG Managed Entries 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG Managed Entries plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libmanagedentries-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG nsslapd-pluginConfigArea: 2019-01-17T11:03:10Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG betxnpreoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG mep_init 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=MemberOf Plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=MemberOf Plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG memberof 2019-01-17T11:03:10Z DEBUG memberofgroupattr: 2019-01-17T11:03:10Z DEBUG member 2019-01-17T11:03:10Z DEBUG memberUser 2019-01-17T11:03:10Z DEBUG memberHost 2019-01-17T11:03:10Z DEBUG memberofentryscope: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG MemberOf Plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG memberof plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libmemberof-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG memberofattr: 2019-01-17T11:03:10Z DEBUG memberOf 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG betxnpostoperation 2019-01-17T11:03:10Z DEBUG memberofentryscopeexcludesubtree: 2019-01-17T11:03:10Z DEBUG cn=compat,dc=local 2019-01-17T11:03:10Z DEBUG cn=provisioning,dc=local 2019-01-17T11:03:10Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG memberof_postop_init 2019-01-17T11:03:10Z DEBUG only: set nsslapd-pluginType to 'betxnpostoperation', current value [u'betxnpostoperation'] 2019-01-17T11:03:10Z DEBUG only: updated value [u'betxnpostoperation'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=MemberOf Plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG memberof 2019-01-17T11:03:10Z DEBUG memberofgroupattr: 2019-01-17T11:03:10Z DEBUG member 2019-01-17T11:03:10Z DEBUG memberUser 2019-01-17T11:03:10Z DEBUG memberHost 2019-01-17T11:03:10Z DEBUG memberofentryscope: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG MemberOf Plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG memberof plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libmemberof-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG memberofattr: 2019-01-17T11:03:10Z DEBUG memberOf 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG betxnpostoperation 2019-01-17T11:03:10Z DEBUG memberofentryscopeexcludesubtree: 2019-01-17T11:03:10Z DEBUG cn=compat,dc=local 2019-01-17T11:03:10Z DEBUG cn=provisioning,dc=local 2019-01-17T11:03:10Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG memberof_postop_init 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=Multimaster Replication Plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=Multimaster Replication Plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG Multimaster Replication Plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG replication_multimaster_plugin_init 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-named: 2019-01-17T11:03:10Z DEBUG ldbm database 2019-01-17T11:03:10Z DEBUG AES 2019-01-17T11:03:10Z DEBUG Class of Service 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG Multi-master Replication Plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libreplication-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG replication-multimaster 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG object 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG only: set nsslapd-pluginbetxn to 'on', current value [u'on'] 2019-01-17T11:03:10Z DEBUG only: updated value [u'on'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=Multimaster Replication Plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG Multimaster Replication Plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG replication_multimaster_plugin_init 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-named: 2019-01-17T11:03:10Z DEBUG ldbm database 2019-01-17T11:03:10Z DEBUG AES 2019-01-17T11:03:10Z DEBUG Class of Service 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG Multi-master Replication Plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libreplication-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG replication-multimaster 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG object 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=PAM Pass Through Auth,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=PAM Pass Through Auth,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG pamFallback: 2019-01-17T11:03:10Z DEBUG FALSE 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG PAM Pass Through Auth 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG pamExcludeSuffix: 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG pamMissingSuffix: 2019-01-17T11:03:10Z DEBUG ALLOW 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libpam-passthru-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG pamConfig 2019-01-17T11:03:10Z DEBUG pamIDMapMethod: 2019-01-17T11:03:10Z DEBUG RDN 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG pamIDAttr: 2019-01-17T11:03:10Z DEBUG notUsedWithRDNMethod 2019-01-17T11:03:10Z DEBUG pamSecure: 2019-01-17T11:03:10Z DEBUG TRUE 2019-01-17T11:03:10Z DEBUG pamService: 2019-01-17T11:03:10Z DEBUG ldapserver 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG betxnpreoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginloadglobal: 2019-01-17T11:03:10Z DEBUG true 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG pam_passthruauth_init 2019-01-17T11:03:10Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value [u'betxnpreoperation'] 2019-01-17T11:03:10Z DEBUG only: updated value [u'betxnpreoperation'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=PAM Pass Through Auth,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG pamFallback: 2019-01-17T11:03:10Z DEBUG FALSE 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG PAM Pass Through Auth 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG pamExcludeSuffix: 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG pamMissingSuffix: 2019-01-17T11:03:10Z DEBUG ALLOW 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libpam-passthru-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG pamConfig 2019-01-17T11:03:10Z DEBUG pamIDMapMethod: 2019-01-17T11:03:10Z DEBUG RDN 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG pamIDAttr: 2019-01-17T11:03:10Z DEBUG notUsedWithRDNMethod 2019-01-17T11:03:10Z DEBUG pamSecure: 2019-01-17T11:03:10Z DEBUG TRUE 2019-01-17T11:03:10Z DEBUG pamService: 2019-01-17T11:03:10Z DEBUG ldapserver 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG betxnpreoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginloadglobal: 2019-01-17T11:03:10Z DEBUG true 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG pam_passthruauth_init 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=referential integrity postoperation,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG referint 2019-01-17T11:03:10Z DEBUG nsslapd-plugincontainerscope: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG referential integrity postoperation 2019-01-17T11:03:10Z DEBUG referint-update-delay: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-pluginexcludeentryscope: 2019-01-17T11:03:10Z DEBUG cn=provisioning,dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG referential integrity plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginentryscope: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libreferint-plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:03:10Z DEBUG 40 2019-01-17T11:03:10Z DEBUG referint-logfile: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/referint 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG betxnpostoperation 2019-01-17T11:03:10Z DEBUG referint-membership-attr: 2019-01-17T11:03:10Z DEBUG member 2019-01-17T11:03:10Z DEBUG uniquemember 2019-01-17T11:03:10Z DEBUG owner 2019-01-17T11:03:10Z DEBUG seeAlso 2019-01-17T11:03:10Z DEBUG manager 2019-01-17T11:03:10Z DEBUG secretary 2019-01-17T11:03:10Z DEBUG memberuser 2019-01-17T11:03:10Z DEBUG memberhost 2019-01-17T11:03:10Z DEBUG sourcehost 2019-01-17T11:03:10Z DEBUG memberservice 2019-01-17T11:03:10Z DEBUG managedby 2019-01-17T11:03:10Z DEBUG memberallowcmd 2019-01-17T11:03:10Z DEBUG memberdenycmd 2019-01-17T11:03:10Z DEBUG ipasudorunas 2019-01-17T11:03:10Z DEBUG ipasudorunasgroup 2019-01-17T11:03:10Z DEBUG ipatokenradiusconfiglink 2019-01-17T11:03:10Z DEBUG ipaassignedidview 2019-01-17T11:03:10Z DEBUG ipaallowedtarget 2019-01-17T11:03:10Z DEBUG ipamemberca 2019-01-17T11:03:10Z DEBUG ipamembercertprofile 2019-01-17T11:03:10Z DEBUG ipalocation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG referint_postop_init 2019-01-17T11:03:10Z DEBUG only: set nsslapd-pluginType to 'betxnpostoperation', current value [u'betxnpostoperation'] 2019-01-17T11:03:10Z DEBUG only: updated value [u'betxnpostoperation'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG referint 2019-01-17T11:03:10Z DEBUG nsslapd-plugincontainerscope: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG referential integrity postoperation 2019-01-17T11:03:10Z DEBUG referint-update-delay: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-pluginexcludeentryscope: 2019-01-17T11:03:10Z DEBUG cn=provisioning,dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG referential integrity plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginentryscope: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libreferint-plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:03:10Z DEBUG 40 2019-01-17T11:03:10Z DEBUG referint-logfile: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/referint 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG betxnpostoperation 2019-01-17T11:03:10Z DEBUG referint-membership-attr: 2019-01-17T11:03:10Z DEBUG member 2019-01-17T11:03:10Z DEBUG uniquemember 2019-01-17T11:03:10Z DEBUG owner 2019-01-17T11:03:10Z DEBUG seeAlso 2019-01-17T11:03:10Z DEBUG manager 2019-01-17T11:03:10Z DEBUG secretary 2019-01-17T11:03:10Z DEBUG memberuser 2019-01-17T11:03:10Z DEBUG memberhost 2019-01-17T11:03:10Z DEBUG sourcehost 2019-01-17T11:03:10Z DEBUG memberservice 2019-01-17T11:03:10Z DEBUG managedby 2019-01-17T11:03:10Z DEBUG memberallowcmd 2019-01-17T11:03:10Z DEBUG memberdenycmd 2019-01-17T11:03:10Z DEBUG ipasudorunas 2019-01-17T11:03:10Z DEBUG ipasudorunasgroup 2019-01-17T11:03:10Z DEBUG ipatokenradiusconfiglink 2019-01-17T11:03:10Z DEBUG ipaassignedidview 2019-01-17T11:03:10Z DEBUG ipaallowedtarget 2019-01-17T11:03:10Z DEBUG ipamemberca 2019-01-17T11:03:10Z DEBUG ipamembercertprofile 2019-01-17T11:03:10Z DEBUG ipalocation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG referint_postop_init 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=Roles Plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=Roles Plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG Roles Plugin 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-named: 2019-01-17T11:03:10Z DEBUG State Change Plugin 2019-01-17T11:03:10Z DEBUG Views 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG roles plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libroles-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG roles 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG roles_init 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG object 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG only: set nsslapd-pluginbetxn to 'on', current value [u'on'] 2019-01-17T11:03:10Z DEBUG only: updated value [u'on'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=Roles Plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG Roles Plugin 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-named: 2019-01-17T11:03:10Z DEBUG State Change Plugin 2019-01-17T11:03:10Z DEBUG Views 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG roles plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libroles-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG roles 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG roles_init 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG object 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=State Change Plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=State Change Plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG statechange 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG State Change Plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG state change notification service plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libstatechange-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG betxnpostoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG statechange_init 2019-01-17T11:03:10Z DEBUG only: set nsslapd-pluginType to 'betxnpostoperation', current value [u'betxnpostoperation'] 2019-01-17T11:03:10Z DEBUG only: updated value [u'betxnpostoperation'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=State Change Plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG statechange 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG State Change Plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG state change notification service plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libstatechange-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG betxnpostoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG statechange_init 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=USN,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=USN,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG USN 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG USN (Update Sequence Number) plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libusn-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG USN 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG usn_init 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG object 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG only: set nsslapd-pluginbetxn to 'on', current value [u'on'] 2019-01-17T11:03:10Z DEBUG only: updated value [u'on'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=USN,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG USN 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG USN (Update Sequence Number) plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libusn-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG USN 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG usn_init 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG object 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=IPA MODRDN,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=IPA MODRDN,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG IPA MODRDN 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG IPA MODRDN 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.0 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG IPA MODRDN plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libipa_modrdn 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG Red Hat, Inc. 2019-01-17T11:03:10Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:03:10Z DEBUG 60 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG betxnpostoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG ipamodrdn_init 2019-01-17T11:03:10Z DEBUG only: set nsslapd-plugintype to 'betxnpostoperation', current value [u'betxnpostoperation'] 2019-01-17T11:03:10Z DEBUG only: updated value [u'betxnpostoperation'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=IPA MODRDN,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG IPA MODRDN 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG IPA MODRDN 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.0 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG IPA MODRDN plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libipa_modrdn 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG Red Hat, Inc. 2019-01-17T11:03:10Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:03:10Z DEBUG 60 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG betxnpostoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG ipamodrdn_init 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=ipa_pwd_extop,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=ipa_pwd_extop,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG ipa_pwd_extop 2019-01-17T11:03:10Z DEBUG nsslapd-realmtree: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG FreeIPA/1.0 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG IPA Password Extended Operation plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libipa_pwd_extop 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG IPA Password Manager 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG ipapwd_init 2019-01-17T11:03:10Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:03:10Z DEBUG 49 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG extendedop 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG FreeIPA project 2019-01-17T11:03:10Z DEBUG only: set nsslapd-pluginbetxn to 'on', current value [u'on'] 2019-01-17T11:03:10Z DEBUG only: updated value [u'on'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=ipa_pwd_extop,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG ipa_pwd_extop 2019-01-17T11:03:10Z DEBUG nsslapd-realmtree: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG FreeIPA/1.0 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG IPA Password Extended Operation plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libipa_pwd_extop 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG IPA Password Manager 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG ipapwd_init 2019-01-17T11:03:10Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:03:10Z DEBUG 49 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG extendedop 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG FreeIPA project 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG Schema Compatibility 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG /usr/lib64/dirsrv/plugins/schemacompat-plugin.so 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG schema_compat_plugin_init 2019-01-17T11:03:10Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:03:10Z DEBUG 40 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG object 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG onlyifexist: 'on' to nsslapd-pluginbetxn, current value [u'on'] 2019-01-17T11:03:10Z DEBUG onlyifexist: set nsslapd-pluginbetxn to [u'on'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG Schema Compatibility 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG /usr/lib64/dirsrv/plugins/schemacompat-plugin.so 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG schema_compat_plugin_init 2019-01-17T11:03:10Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:03:10Z DEBUG 40 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG object 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG New entry: cn=NIS Server,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=NIS Server,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG onlyifexist: 'on' to nsslapd-pluginbetxn, current value [] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=NIS Server,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG Parsing update file '/usr/share/ipa/updates/10-ipapwd.update' 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=ipa_pwd_extop,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=ipa_pwd_extop,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG ipa_pwd_extop 2019-01-17T11:03:10Z DEBUG nsslapd-realmtree: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG FreeIPA/1.0 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG IPA Password Extended Operation plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libipa_pwd_extop 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG IPA Password Manager 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG ipapwd_init 2019-01-17T11:03:10Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:03:10Z DEBUG 49 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG extendedop 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG FreeIPA project 2019-01-17T11:03:10Z DEBUG add: '49' to nsslapd-pluginprecedence, current value [u'49'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'49'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=ipa_pwd_extop,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG ipa_pwd_extop 2019-01-17T11:03:10Z DEBUG nsslapd-realmtree: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG FreeIPA/1.0 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG IPA Password Extended Operation plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libipa_pwd_extop 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG IPA Password Manager 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG ipapwd_init 2019-01-17T11:03:10Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:03:10Z DEBUG 49 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG extendedop 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG FreeIPA project 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Parsing update file '/usr/share/ipa/updates/10-rootdse.update' 2019-01-17T11:03:10Z DEBUG Updating existing entry: 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: 2019-01-17T11:03:10Z DEBUG netscapemdsuffix: 2019-01-17T11:03:10Z DEBUG cn=ldap://dc=centos75,dc=local:0 2019-01-17T11:03:10Z DEBUG supportedLDAPVersion: 2019-01-17T11:03:10Z DEBUG 2 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG ipaDomainLevel: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr != "aci")(version 3.0; aci "rootdse anon read access"; allow(read,search,compare) userdn="ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG dataversion: 2019-01-17T11:03:10Z DEBUG 020190117110306020190117110306020190117110306 2019-01-17T11:03:10Z DEBUG lastusn: 2019-01-17T11:03:10Z DEBUG 478 2019-01-17T11:03:10Z DEBUG vendorName: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG supportedSASLMechanisms: 2019-01-17T11:03:10Z DEBUG EXTERNAL 2019-01-17T11:03:10Z DEBUG SCRAM-SHA-1 2019-01-17T11:03:10Z DEBUG GSS-SPNEGO 2019-01-17T11:03:10Z DEBUG GSSAPI 2019-01-17T11:03:10Z DEBUG DIGEST-MD5 2019-01-17T11:03:10Z DEBUG CRAM-MD5 2019-01-17T11:03:10Z DEBUG LOGIN 2019-01-17T11:03:10Z DEBUG PLAIN 2019-01-17T11:03:10Z DEBUG ANONYMOUS 2019-01-17T11:03:10Z DEBUG lastchangenumber: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG defaultnamingcontext: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG ipatopologyismanaged: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG supportedExtension: 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.5.7 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.5.8 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.5.10 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.8.10.3 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.8.10.4 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.8.10.4.1 2019-01-17T11:03:10Z DEBUG 1.3.6.1.4.1.4203.1.11.1 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.8.10.1 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.8.10.5 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.5.3 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.5.12 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.5.5 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.5.6 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.5.9 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.5.4 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.6.5 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.6.6 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.6.7 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.6.8 2019-01-17T11:03:10Z DEBUG 1.3.6.1.4.1.4203.1.11.3 2019-01-17T11:03:10Z DEBUG supportedControl: 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.4.2 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.4.3 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.4.4 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.4.5 2019-01-17T11:03:10Z DEBUG 1.2.840.113556.1.4.473 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.4.9 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.4.16 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.4.15 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.4.17 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.4.19 2019-01-17T11:03:10Z DEBUG 1.3.6.1.1.13.1 2019-01-17T11:03:10Z DEBUG 1.3.6.1.1.13.2 2019-01-17T11:03:10Z DEBUG 1.3.6.1.4.1.42.2.27.8.5.1 2019-01-17T11:03:10Z DEBUG 1.3.6.1.4.1.42.2.27.9.5.2 2019-01-17T11:03:10Z DEBUG 1.2.840.113556.1.4.319 2019-01-17T11:03:10Z DEBUG 1.3.6.1.4.1.42.2.27.9.5.8 2019-01-17T11:03:10Z DEBUG 1.3.6.1.4.1.4203.666.5.16 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.8.10.6 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.8.10.7 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.4.14 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.4.20 2019-01-17T11:03:10Z DEBUG 1.3.6.1.4.1.1466.29539.12 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.4.12 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.4.18 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.4.13 2019-01-17T11:03:10Z DEBUG 1.3.6.1.4.1.4203.1.9.1.1 2019-01-17T11:03:10Z DEBUG changeLog: 2019-01-17T11:03:10Z DEBUG cn=changelog 2019-01-17T11:03:10Z DEBUG ipatopologypluginversion: 2019-01-17T11:03:10Z DEBUG 1.0 2019-01-17T11:03:10Z DEBUG firstchangenumber: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG namingContexts: 2019-01-17T11:03:10Z DEBUG cn=changelog 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG o=ipaca 2019-01-17T11:03:10Z DEBUG vendorVersion: 2019-01-17T11:03:10Z DEBUG 389-Directory/1.3.8.4 B2018.332.2046 2019-01-17T11:03:10Z DEBUG add: 'namingContexts' to nsslapd-return-default-opattr, current value [] 2019-01-17T11:03:10Z DEBUG add: updated value [u'namingContexts'] 2019-01-17T11:03:10Z DEBUG add: 'supportedControl' to nsslapd-return-default-opattr, current value [u'namingContexts'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'namingContexts', u'supportedControl'] 2019-01-17T11:03:10Z DEBUG add: 'supportedExtension' to nsslapd-return-default-opattr, current value [u'namingContexts', u'supportedControl'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'namingContexts', u'supportedControl', u'supportedExtension'] 2019-01-17T11:03:10Z DEBUG add: 'supportedLDAPVersion' to nsslapd-return-default-opattr, current value [u'namingContexts', u'supportedControl', u'supportedExtension'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'namingContexts', u'supportedControl', u'supportedExtension', u'supportedLDAPVersion'] 2019-01-17T11:03:10Z DEBUG add: 'supportedSASLMechanisms' to nsslapd-return-default-opattr, current value [u'namingContexts', u'supportedControl', u'supportedExtension', u'supportedLDAPVersion'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'namingContexts', u'supportedControl', u'supportedExtension', u'supportedLDAPVersion', u'supportedSASLMechanisms'] 2019-01-17T11:03:10Z DEBUG add: 'vendorName' to nsslapd-return-default-opattr, current value [u'namingContexts', u'supportedControl', u'supportedExtension', u'supportedLDAPVersion', u'supportedSASLMechanisms'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'namingContexts', u'supportedControl', u'supportedExtension', u'supportedLDAPVersion', u'supportedSASLMechanisms', u'vendorName'] 2019-01-17T11:03:10Z DEBUG add: 'vendorVersion' to nsslapd-return-default-opattr, current value [u'namingContexts', u'supportedControl', u'supportedExtension', u'supportedLDAPVersion', u'supportedSASLMechanisms', u'vendorName'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'namingContexts', u'supportedControl', u'supportedExtension', u'supportedLDAPVersion', u'supportedSASLMechanisms', u'vendorName', u'vendorVersion'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: 2019-01-17T11:03:10Z DEBUG netscapemdsuffix: 2019-01-17T11:03:10Z DEBUG cn=ldap://dc=centos75,dc=local:0 2019-01-17T11:03:10Z DEBUG supportedLDAPVersion: 2019-01-17T11:03:10Z DEBUG 2 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG ipaDomainLevel: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr != "aci")(version 3.0; aci "rootdse anon read access"; allow(read,search,compare) userdn="ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG dataversion: 2019-01-17T11:03:10Z DEBUG 020190117110306020190117110306020190117110306 2019-01-17T11:03:10Z DEBUG lastusn: 2019-01-17T11:03:10Z DEBUG 478 2019-01-17T11:03:10Z DEBUG vendorName: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG supportedSASLMechanisms: 2019-01-17T11:03:10Z DEBUG EXTERNAL 2019-01-17T11:03:10Z DEBUG SCRAM-SHA-1 2019-01-17T11:03:10Z DEBUG GSS-SPNEGO 2019-01-17T11:03:10Z DEBUG GSSAPI 2019-01-17T11:03:10Z DEBUG DIGEST-MD5 2019-01-17T11:03:10Z DEBUG CRAM-MD5 2019-01-17T11:03:10Z DEBUG LOGIN 2019-01-17T11:03:10Z DEBUG PLAIN 2019-01-17T11:03:10Z DEBUG ANONYMOUS 2019-01-17T11:03:10Z DEBUG lastchangenumber: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG defaultnamingcontext: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG ipatopologyismanaged: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG supportedExtension: 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.5.7 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.5.8 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.5.10 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.8.10.3 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.8.10.4 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.8.10.4.1 2019-01-17T11:03:10Z DEBUG 1.3.6.1.4.1.4203.1.11.1 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.8.10.1 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.8.10.5 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.5.3 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.5.12 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.5.5 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.5.6 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.5.9 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.5.4 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.6.5 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.6.6 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.6.7 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.6.8 2019-01-17T11:03:10Z DEBUG 1.3.6.1.4.1.4203.1.11.3 2019-01-17T11:03:10Z DEBUG nsslapd-return-default-opattr: 2019-01-17T11:03:10Z DEBUG namingContexts 2019-01-17T11:03:10Z DEBUG supportedControl 2019-01-17T11:03:10Z DEBUG supportedExtension 2019-01-17T11:03:10Z DEBUG supportedLDAPVersion 2019-01-17T11:03:10Z DEBUG supportedSASLMechanisms 2019-01-17T11:03:10Z DEBUG vendorName 2019-01-17T11:03:10Z DEBUG vendorVersion 2019-01-17T11:03:10Z DEBUG supportedControl: 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.4.2 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.4.3 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.4.4 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.4.5 2019-01-17T11:03:10Z DEBUG 1.2.840.113556.1.4.473 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.4.9 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.4.16 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.4.15 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.4.17 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.4.19 2019-01-17T11:03:10Z DEBUG 1.3.6.1.1.13.1 2019-01-17T11:03:10Z DEBUG 1.3.6.1.1.13.2 2019-01-17T11:03:10Z DEBUG 1.3.6.1.4.1.42.2.27.8.5.1 2019-01-17T11:03:10Z DEBUG 1.3.6.1.4.1.42.2.27.9.5.2 2019-01-17T11:03:10Z DEBUG 1.2.840.113556.1.4.319 2019-01-17T11:03:10Z DEBUG 1.3.6.1.4.1.42.2.27.9.5.8 2019-01-17T11:03:10Z DEBUG 1.3.6.1.4.1.4203.666.5.16 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.8.10.6 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.8.10.7 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.4.14 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.4.20 2019-01-17T11:03:10Z DEBUG 1.3.6.1.4.1.1466.29539.12 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.4.12 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.4.18 2019-01-17T11:03:10Z DEBUG 2.16.840.1.113730.3.4.13 2019-01-17T11:03:10Z DEBUG 1.3.6.1.4.1.4203.1.9.1.1 2019-01-17T11:03:10Z DEBUG changeLog: 2019-01-17T11:03:10Z DEBUG cn=changelog 2019-01-17T11:03:10Z DEBUG ipatopologypluginversion: 2019-01-17T11:03:10Z DEBUG 1.0 2019-01-17T11:03:10Z DEBUG firstchangenumber: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG namingContexts: 2019-01-17T11:03:10Z DEBUG cn=changelog 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG o=ipaca 2019-01-17T11:03:10Z DEBUG vendorVersion: 2019-01-17T11:03:10Z DEBUG 389-Directory/1.3.8.4 B2018.332.2046 2019-01-17T11:03:10Z DEBUG [(2, u'nsslapd-return-default-opattr', [u'namingContexts', u'supportedControl', u'supportedExtension', u'supportedLDAPVersion', u'supportedSASLMechanisms', u'vendorName', u'vendorVersion'])] 2019-01-17T11:03:10Z DEBUG Updated 1 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Parsing update file '/usr/share/ipa/updates/10-selinuxusermap.update' 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=selinux,dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=selinux,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG selinux 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=selinux,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG selinux 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=usermap,cn=selinux,dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=usermap,cn=selinux,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG usermap 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=usermap,cn=selinux,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG usermap 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Parsing update file '/usr/share/ipa/updates/10-uniqueness.update' 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=sudorule name uniqueness,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=sudorule name uniqueness,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG uniqueness-attribute-name: 2019-01-17T11:03:10Z DEBUG cn 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG NSUniqueAttr 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG sudorule name uniqueness 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG Enforce unique attribute values 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libattr-unique-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG uniqueness-subtrees: 2019-01-17T11:03:10Z DEBUG cn=sudorules,cn=sudo,dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG preoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG NSUniqueAttr_Init 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=sudorule name uniqueness,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG uniqueness-attribute-name: 2019-01-17T11:03:10Z DEBUG cn 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG NSUniqueAttr 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG sudorule name uniqueness 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG Enforce unique attribute values 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libattr-unique-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG uniqueness-subtrees: 2019-01-17T11:03:10Z DEBUG cn=sudorules,cn=sudo,dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG preoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG NSUniqueAttr_Init 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=certificate store subject uniqueness,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=certificate store subject uniqueness,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG uniqueness-attribute-name: 2019-01-17T11:03:10Z DEBUG ipaCertSubject 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG NSUniqueAttr 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG certificate store subject uniqueness 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG Enforce unique attribute values 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libattr-unique-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG uniqueness-subtrees: 2019-01-17T11:03:10Z DEBUG cn=certificates,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG preoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG NSUniqueAttr_Init 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=certificate store subject uniqueness,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG uniqueness-attribute-name: 2019-01-17T11:03:10Z DEBUG ipaCertSubject 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG NSUniqueAttr 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG certificate store subject uniqueness 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG Enforce unique attribute values 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libattr-unique-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG uniqueness-subtrees: 2019-01-17T11:03:10Z DEBUG cn=certificates,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG preoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG NSUniqueAttr_Init 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=certificate store issuer/serial uniqueness,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=certificate store issuer/serial uniqueness,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG uniqueness-attribute-name: 2019-01-17T11:03:10Z DEBUG ipaCertIssuerSerial 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG NSUniqueAttr 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG certificate store issuer/serial uniqueness 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG Enforce unique attribute values 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libattr-unique-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG uniqueness-subtrees: 2019-01-17T11:03:10Z DEBUG cn=certificates,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG preoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG NSUniqueAttr_Init 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=certificate store issuer/serial uniqueness,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG uniqueness-attribute-name: 2019-01-17T11:03:10Z DEBUG ipaCertIssuerSerial 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG NSUniqueAttr 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG certificate store issuer/serial uniqueness 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG Enforce unique attribute values 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libattr-unique-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG uniqueness-subtrees: 2019-01-17T11:03:10Z DEBUG cn=certificates,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG preoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG NSUniqueAttr_Init 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=uid uniqueness,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=uid uniqueness,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG uniqueness-attribute-name: 2019-01-17T11:03:10Z DEBUG uid 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG NSUniqueAttr 2019-01-17T11:03:10Z DEBUG uniqueness-subtree-entries-oc: 2019-01-17T11:03:10Z DEBUG posixAccount 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG uid uniqueness 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG Enforce unique attribute values 2019-01-17T11:03:10Z DEBUG uniqueness-across-all-subtrees: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libattr-unique-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG uniqueness-exclude-subtrees: 2019-01-17T11:03:10Z DEBUG cn=compat,dc=local 2019-01-17T11:03:10Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:10Z DEBUG uniqueness-subtrees: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG preoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG NSUniqueAttr_Init 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=uid uniqueness,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG uniqueness-attribute-name: 2019-01-17T11:03:10Z DEBUG uid 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG NSUniqueAttr 2019-01-17T11:03:10Z DEBUG uniqueness-subtree-entries-oc: 2019-01-17T11:03:10Z DEBUG posixAccount 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG uid uniqueness 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG Enforce unique attribute values 2019-01-17T11:03:10Z DEBUG uniqueness-across-all-subtrees: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libattr-unique-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG uniqueness-exclude-subtrees: 2019-01-17T11:03:10Z DEBUG cn=compat,dc=local 2019-01-17T11:03:10Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:10Z DEBUG uniqueness-subtrees: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG preoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG NSUniqueAttr_Init 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=uid uniqueness,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=uid uniqueness,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG uniqueness-attribute-name: 2019-01-17T11:03:10Z DEBUG uid 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG NSUniqueAttr 2019-01-17T11:03:10Z DEBUG uniqueness-subtree-entries-oc: 2019-01-17T11:03:10Z DEBUG posixAccount 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG uid uniqueness 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG Enforce unique attribute values 2019-01-17T11:03:10Z DEBUG uniqueness-across-all-subtrees: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libattr-unique-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG uniqueness-exclude-subtrees: 2019-01-17T11:03:10Z DEBUG cn=compat,dc=local 2019-01-17T11:03:10Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:10Z DEBUG uniqueness-subtrees: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG preoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG NSUniqueAttr_Init 2019-01-17T11:03:10Z DEBUG add: 'cn=compat,dc=local' to uniqueness-exclude-subtrees, current value [u'cn=compat,dc=local', u'cn=staged users,cn=accounts,cn=provisioning,dc=local'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'cn=staged users,cn=accounts,cn=provisioning,dc=local', u'cn=compat,dc=local'] 2019-01-17T11:03:10Z DEBUG add: 'cn=staged users,cn=accounts,cn=provisioning,dc=local' to uniqueness-exclude-subtrees, current value [u'cn=staged users,cn=accounts,cn=provisioning,dc=local', u'cn=compat,dc=local'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'cn=compat,dc=local', u'cn=staged users,cn=accounts,cn=provisioning,dc=local'] 2019-01-17T11:03:10Z DEBUG remove: 'off' from uniqueness-across-all-subtrees, current value [u'on'] 2019-01-17T11:03:10Z DEBUG remove: 'off' not in uniqueness-across-all-subtrees 2019-01-17T11:03:10Z DEBUG add: 'on' to uniqueness-across-all-subtrees, current value [u'on'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'on'] 2019-01-17T11:03:10Z DEBUG add: 'posixAccount' to uniqueness-subtree-entries-oc, current value [u'posixAccount'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'posixAccount'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=uid uniqueness,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG uniqueness-attribute-name: 2019-01-17T11:03:10Z DEBUG uid 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG NSUniqueAttr 2019-01-17T11:03:10Z DEBUG uniqueness-subtree-entries-oc: 2019-01-17T11:03:10Z DEBUG posixAccount 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG uid uniqueness 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG Enforce unique attribute values 2019-01-17T11:03:10Z DEBUG uniqueness-across-all-subtrees: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libattr-unique-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG uniqueness-exclude-subtrees: 2019-01-17T11:03:10Z DEBUG cn=compat,dc=local 2019-01-17T11:03:10Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:10Z DEBUG uniqueness-subtrees: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG preoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG NSUniqueAttr_Init 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=krbPrincipalName uniqueness,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=krbPrincipalName uniqueness,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG uniqueness-attribute-name: 2019-01-17T11:03:10Z DEBUG krbPrincipalName 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG NSUniqueAttr 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG krbPrincipalName uniqueness 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG Enforce unique attribute values 2019-01-17T11:03:10Z DEBUG uniqueness-across-all-subtrees: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libattr-unique-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG uniqueness-exclude-subtrees: 2019-01-17T11:03:10Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:10Z DEBUG uniqueness-subtrees: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG preoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG NSUniqueAttr_Init 2019-01-17T11:03:10Z DEBUG add: 'cn=staged users,cn=accounts,cn=provisioning,dc=local' to uniqueness-exclude-subtrees, current value [u'cn=staged users,cn=accounts,cn=provisioning,dc=local'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'cn=staged users,cn=accounts,cn=provisioning,dc=local'] 2019-01-17T11:03:10Z DEBUG add: 'on' to uniqueness-across-all-subtrees, current value [u'on'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'on'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=krbPrincipalName uniqueness,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG uniqueness-attribute-name: 2019-01-17T11:03:10Z DEBUG krbPrincipalName 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG NSUniqueAttr 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG krbPrincipalName uniqueness 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG Enforce unique attribute values 2019-01-17T11:03:10Z DEBUG uniqueness-across-all-subtrees: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libattr-unique-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG uniqueness-exclude-subtrees: 2019-01-17T11:03:10Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:10Z DEBUG uniqueness-subtrees: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG preoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG NSUniqueAttr_Init 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=krbCanonicalName uniqueness,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=krbCanonicalName uniqueness,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG uniqueness-attribute-name: 2019-01-17T11:03:10Z DEBUG krbCanonicalName 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG NSUniqueAttr 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG krbCanonicalName uniqueness 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG Enforce unique attribute values 2019-01-17T11:03:10Z DEBUG uniqueness-across-all-subtrees: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libattr-unique-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG uniqueness-exclude-subtrees: 2019-01-17T11:03:10Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:10Z DEBUG uniqueness-subtrees: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG preoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG NSUniqueAttr_Init 2019-01-17T11:03:10Z DEBUG add: 'cn=staged users,cn=accounts,cn=provisioning,dc=local' to uniqueness-exclude-subtrees, current value [u'cn=staged users,cn=accounts,cn=provisioning,dc=local'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'cn=staged users,cn=accounts,cn=provisioning,dc=local'] 2019-01-17T11:03:10Z DEBUG add: 'on' to uniqueness-across-all-subtrees, current value [u'on'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'on'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=krbCanonicalName uniqueness,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG uniqueness-attribute-name: 2019-01-17T11:03:10Z DEBUG krbCanonicalName 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG NSUniqueAttr 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG krbCanonicalName uniqueness 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG Enforce unique attribute values 2019-01-17T11:03:10Z DEBUG uniqueness-across-all-subtrees: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libattr-unique-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG uniqueness-exclude-subtrees: 2019-01-17T11:03:10Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:10Z DEBUG uniqueness-subtrees: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG preoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG NSUniqueAttr_Init 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=ipaUniqueID uniqueness,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=ipaUniqueID uniqueness,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG uniqueness-attribute-name: 2019-01-17T11:03:10Z DEBUG ipaUniqueID 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG NSUniqueAttr 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG ipaUniqueID uniqueness 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG Enforce unique attribute values 2019-01-17T11:03:10Z DEBUG uniqueness-across-all-subtrees: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libattr-unique-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG uniqueness-exclude-subtrees: 2019-01-17T11:03:10Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:10Z DEBUG uniqueness-subtrees: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG preoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG NSUniqueAttr_Init 2019-01-17T11:03:10Z DEBUG add: 'cn=staged users,cn=accounts,cn=provisioning,dc=local' to uniqueness-exclude-subtrees, current value [u'cn=staged users,cn=accounts,cn=provisioning,dc=local'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'cn=staged users,cn=accounts,cn=provisioning,dc=local'] 2019-01-17T11:03:10Z DEBUG add: 'on' to uniqueness-across-all-subtrees, current value [u'on'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'on'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=ipaUniqueID uniqueness,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG uniqueness-attribute-name: 2019-01-17T11:03:10Z DEBUG ipaUniqueID 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG NSUniqueAttr 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG ipaUniqueID uniqueness 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG Enforce unique attribute values 2019-01-17T11:03:10Z DEBUG uniqueness-across-all-subtrees: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libattr-unique-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG uniqueness-exclude-subtrees: 2019-01-17T11:03:10Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:10Z DEBUG uniqueness-subtrees: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG preoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG NSUniqueAttr_Init 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Parsing update file '/usr/share/ipa/updates/19-managed-entries.update' 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=Managed Entries,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG Managed Entries 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG Managed Entries 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG Managed Entries plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libmanagedentries-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG nsslapd-pluginConfigArea: 2019-01-17T11:03:10Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG betxnpreoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG mep_init 2019-01-17T11:03:10Z DEBUG only: set nsslapd-pluginConfigArea to 'cn=Definitions,cn=Managed Entries,cn=etc,dc=local', current value [u'cn=Definitions,cn=Managed Entries,cn=etc,dc=local'] 2019-01-17T11:03:10Z DEBUG only: updated value [u'cn=Definitions,cn=Managed Entries,cn=etc,dc=local'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:10Z DEBUG Managed Entries 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG Managed Entries 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:10Z DEBUG 1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:10Z DEBUG Managed Entries plugin 2019-01-17T11:03:10Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:10Z DEBUG libmanagedentries-plugin 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsSlapdPlugin 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:10Z DEBUG database 2019-01-17T11:03:10Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:10Z DEBUG 389 Project 2019-01-17T11:03:10Z DEBUG nsslapd-pluginConfigArea: 2019-01-17T11:03:10Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:10Z DEBUG betxnpreoperation 2019-01-17T11:03:10Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:10Z DEBUG mep_init 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG Managed Entries 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG Managed Entries 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=Templates,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=Templates,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG Templates 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=Templates,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG Templates 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG Definitions 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG Definitions 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Parsing update file '/usr/share/ipa/updates/20-aci.update' 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=ng,cn=alt,dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=ng,cn=alt,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG ng 2019-01-17T11:03:10Z DEBUG add: '(targetfilter = "(objectClass=mepManagedEntry)")(targetattr = "*")(version 3.0; acl "Managed netgroups cannot be modified"; deny (write) userdn = "ldap:///all";)' to aci, current value [] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetfilter = "(objectClass=mepManagedEntry)")(targetattr = "*")(version 3.0; acl "Managed netgroups cannot be modified"; deny (write) userdn = "ldap:///all";)'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=ng,cn=alt,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=mepManagedEntry)")(targetattr = "*")(version 3.0; acl "Managed netgroups cannot be modified"; deny (write) userdn = "ldap:///all";) 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG ng 2019-01-17T11:03:10Z DEBUG [(2, u'aci', [u'(targetfilter = "(objectClass=mepManagedEntry)")(targetattr = "*")(version 3.0; acl "Managed netgroups cannot be modified"; deny (write) userdn = "ldap:///all";)'])] 2019-01-17T11:03:10Z DEBUG Updated 1 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=accounts,dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=accounts,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";) 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG accounts 2019-01-17T11:03:10Z DEBUG add: '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)' to aci, current value [u'(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=accounts,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";) 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG accounts 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG domain 2019-01-17T11:03:10Z DEBUG pilotObject 2019-01-17T11:03:10Z DEBUG info: 2019-01-17T11:03:10Z DEBUG IPA V2.0 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG dc: 2019-01-17T11:03:10Z DEBUG local 2019-01-17T11:03:10Z DEBUG add: '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG domain 2019-01-17T11:03:10Z DEBUG pilotObject 2019-01-17T11:03:10Z DEBUG info: 2019-01-17T11:03:10Z DEBUG IPA V2.0 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG dc: 2019-01-17T11:03:10Z DEBUG local 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=computers,cn=accounts,dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=computers,cn=accounts,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=local")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG computers 2019-01-17T11:03:10Z DEBUG add: '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";)' to aci, current value [u'(targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";)', u'(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";)', u'(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', u'(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', u'(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=local")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";)', u'(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', u'(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', u'(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=local")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";)'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=computers,cn=accounts,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=local")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG computers 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=computers,cn=accounts,dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=computers,cn=accounts,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=local")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG computers 2019-01-17T11:03:10Z DEBUG add: '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)' to aci, current value [u'(targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";)', u'(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";)', u'(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', u'(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', u'(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=local")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";)', u'(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";)', u'(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', u'(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=local")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=computers,cn=accounts,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=local")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG computers 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG domain 2019-01-17T11:03:10Z DEBUG pilotObject 2019-01-17T11:03:10Z DEBUG info: 2019-01-17T11:03:10Z DEBUG IPA V2.0 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG dc: 2019-01-17T11:03:10Z DEBUG local 2019-01-17T11:03:10Z DEBUG add: '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG domain 2019-01-17T11:03:10Z DEBUG pilotObject 2019-01-17T11:03:10Z DEBUG info: 2019-01-17T11:03:10Z DEBUG IPA V2.0 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2019-01-17T11:03:10Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG dc: 2019-01-17T11:03:10Z DEBUG local 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG domain 2019-01-17T11:03:10Z DEBUG pilotObject 2019-01-17T11:03:10Z DEBUG info: 2019-01-17T11:03:10Z DEBUG IPA V2.0 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG dc: 2019-01-17T11:03:10Z DEBUG local 2019-01-17T11:03:10Z DEBUG add: '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG domain 2019-01-17T11:03:10Z DEBUG pilotObject 2019-01-17T11:03:10Z DEBUG info: 2019-01-17T11:03:10Z DEBUG IPA V2.0 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG dc: 2019-01-17T11:03:10Z DEBUG local 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG domain 2019-01-17T11:03:10Z DEBUG pilotObject 2019-01-17T11:03:10Z DEBUG info: 2019-01-17T11:03:10Z DEBUG IPA V2.0 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG dc: 2019-01-17T11:03:10Z DEBUG local 2019-01-17T11:03:10Z DEBUG add: '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG domain 2019-01-17T11:03:10Z DEBUG pilotObject 2019-01-17T11:03:10Z DEBUG info: 2019-01-17T11:03:10Z DEBUG IPA V2.0 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG dc: 2019-01-17T11:03:10Z DEBUG local 2019-01-17T11:03:10Z DEBUG [(0, u'aci', [u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'])] 2019-01-17T11:03:10Z DEBUG Updated 1 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=replicas,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=replicas,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG replicas 2019-01-17T11:03:10Z DEBUG remove: '(targetfilter="(objectclass=nsContainer)")(version 3.0; acl "Deny read access to replica configuration"; deny(read, search, compare) userdn = "ldap:///anyone";)' from aci, current value [] 2019-01-17T11:03:10Z DEBUG remove: '(targetfilter="(objectclass=nsContainer)")(version 3.0; acl "Deny read access to replica configuration"; deny(read, search, compare) userdn = "ldap:///anyone";)' not in aci 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=replicas,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG replicas 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG masters 2019-01-17T11:03:10Z DEBUG add: '(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)' to aci, current value [] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG masters 2019-01-17T11:03:10Z DEBUG [(2, u'aci', [u'(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)'])] 2019-01-17T11:03:10Z DEBUG Updated 1 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG masters 2019-01-17T11:03:10Z DEBUG add: '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=local";)' to aci, current value [u'(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', u'(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG masters 2019-01-17T11:03:10Z DEBUG [(0, u'aci', [u'(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=local";)'])] 2019-01-17T11:03:10Z DEBUG Updated 1 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG sysaccounts 2019-01-17T11:03:10Z DEBUG add: '(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=local")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=local";)' to aci, current value [] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=local")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=local")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG sysaccounts 2019-01-17T11:03:10Z DEBUG [(2, u'aci', [u'(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=local")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=local";)'])] 2019-01-17T11:03:10Z DEBUG Updated 1 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=kerberos,dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=kerberos,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG krbContainer 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG kerberos 2019-01-17T11:03:10Z DEBUG add: '(targetattr = "cn || objectclass")(targetfilter = "(|(objectclass=krbrealmcontainer)(objectclass=krbcontainer))")(version 3.0;acl "Anonymous read access to Kerberos containers";allow (read,compare,search) userdn = "ldap:///anyone";)' to aci, current value [] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetattr = "cn || objectclass")(targetfilter = "(|(objectclass=krbrealmcontainer)(objectclass=krbcontainer))")(version 3.0;acl "Anonymous read access to Kerberos containers";allow (read,compare,search) userdn = "ldap:///anyone";)'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=kerberos,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG krbContainer 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || objectclass")(targetfilter = "(|(objectclass=krbrealmcontainer)(objectclass=krbcontainer))")(version 3.0;acl "Anonymous read access to Kerberos containers";allow (read,compare,search) userdn = "ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG kerberos 2019-01-17T11:03:10Z DEBUG [(2, u'aci', [u'(targetattr = "cn || objectclass")(targetfilter = "(|(objectclass=krbrealmcontainer)(objectclass=krbcontainer))")(version 3.0;acl "Anonymous read access to Kerberos containers";allow (read,compare,search) userdn = "ldap:///anyone";)'])] 2019-01-17T11:03:10Z DEBUG Updated 1 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG domain 2019-01-17T11:03:10Z DEBUG pilotObject 2019-01-17T11:03:10Z DEBUG info: 2019-01-17T11:03:10Z DEBUG IPA V2.0 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG dc: 2019-01-17T11:03:10Z DEBUG local 2019-01-17T11:03:10Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || krbTicketFlags || ipaUniqueId || memberOf || serverHostName || enrolledBy")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' from aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2019-01-17T11:03:10Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || krbTicketFlags || ipaUniqueId || memberOf || serverHostName || enrolledBy")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' not in aci 2019-01-17T11:03:10Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || krbTicketFlags || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' from aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2019-01-17T11:03:10Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || krbTicketFlags || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' not in aci 2019-01-17T11:03:10Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' from aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2019-01-17T11:03:10Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' not in aci 2019-01-17T11:03:10Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' from aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2019-01-17T11:03:10Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' not in aci 2019-01-17T11:03:10Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' from aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2019-01-17T11:03:10Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' not in aci 2019-01-17T11:03:10Z DEBUG add: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG remove: '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' from aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG remove: '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' not in aci 2019-01-17T11:03:10Z DEBUG remove: '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' from aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG remove: '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' not in aci 2019-01-17T11:03:10Z DEBUG add: '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG add: '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG add: '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG add: '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG domain 2019-01-17T11:03:10Z DEBUG pilotObject 2019-01-17T11:03:10Z DEBUG info: 2019-01-17T11:03:10Z DEBUG IPA V2.0 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG dc: 2019-01-17T11:03:10Z DEBUG local 2019-01-17T11:03:10Z DEBUG [(0, u'aci', [u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'])] 2019-01-17T11:03:10Z DEBUG Updated 1 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=tasks,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=tasks,cn=config 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr=*)(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr=*)(version 3.0; acl "cert manager: Run tasks after replica re-initialization"; allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:03:10Z DEBUG (targetattr="*")(version 3.0; acl "Admin can read all tasks"; allow (read, compare, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "*")(target = "ldap:///cn=*,cn=automember rebuild membership,cn=tasks,cn=config")(version 3.0;acl "permission:System: Read Automember Tasks";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Automember Tasks,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG tasks 2019-01-17T11:03:10Z DEBUG add: '(targetattr="*")(version 3.0; acl "Admin can read all tasks"; allow (read, compare, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' to aci, current value [u'(targetattr=*)(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(version 3.0; acl "cert manager: Run tasks after replica re-initialization"; allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(targetattr="*")(version 3.0; acl "Admin can read all tasks"; allow (read, compare, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "*")(target = "ldap:///cn=*,cn=automember rebuild membership,cn=tasks,cn=config")(version 3.0;acl "permission:System: Read Automember Tasks";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Automember Tasks,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetattr=*)(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(version 3.0; acl "cert manager: Run tasks after replica re-initialization"; allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(targetattr = "*")(target = "ldap:///cn=*,cn=automember rebuild membership,cn=tasks,cn=config")(version 3.0;acl "permission:System: Read Automember Tasks";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Automember Tasks,cn=permissions,cn=pbac,dc=local";)', u'(targetattr="*")(version 3.0; acl "Admin can read all tasks"; allow (read, compare, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=tasks,cn=config 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr=*)(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr=*)(version 3.0; acl "cert manager: Run tasks after replica re-initialization"; allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:03:10Z DEBUG (targetattr = "*")(target = "ldap:///cn=*,cn=automember rebuild membership,cn=tasks,cn=config")(version 3.0;acl "permission:System: Read Automember Tasks";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Automember Tasks,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr="*")(version 3.0; acl "Admin can read all tasks"; allow (read, compare, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG tasks 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=mapping tree,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=mapping tree,cn=config 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG mapping tree 2019-01-17T11:03:10Z DEBUG add: '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)' to aci, current value [u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=mapping tree,cn=config 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG mapping tree 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=mapping tree,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=mapping tree,cn=config 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG mapping tree 2019-01-17T11:03:10Z DEBUG add: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";)' to aci, current value [u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:10Z DEBUG add: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)' to aci, current value [u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:10Z DEBUG add: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";)' to aci, current value [u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:10Z DEBUG add: '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=local";)' to aci, current value [u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=mapping tree,cn=config 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG mapping tree 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=dc\=local,cn=mapping tree,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=dc\=local,cn=mapping tree,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-state: 2019-01-17T11:03:10Z DEBUG backend 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsMappingTree 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG "dc=local" 2019-01-17T11:03:10Z DEBUG nsslapd-backend: 2019-01-17T11:03:10Z DEBUG userRoot 2019-01-17T11:03:10Z DEBUG remove: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";)' from aci, current value [] 2019-01-17T11:03:10Z DEBUG remove: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";)' not in aci 2019-01-17T11:03:10Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)' from aci, current value [] 2019-01-17T11:03:10Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)' not in aci 2019-01-17T11:03:10Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";)' from aci, current value [] 2019-01-17T11:03:10Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";)' not in aci 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=dc\=local,cn=mapping tree,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-state: 2019-01-17T11:03:10Z DEBUG backend 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsMappingTree 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG "dc=local" 2019-01-17T11:03:10Z DEBUG nsslapd-backend: 2019-01-17T11:03:10Z DEBUG userRoot 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=o\=ipaca,cn=mapping tree,cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=o\=ipaca,cn=mapping tree,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-state: 2019-01-17T11:03:10Z DEBUG Backend 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsMappingTree 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr=*)(version 3.0;acl "cert manager: Add Replication Agreements";allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:03:10Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "cert manager: Modify Replication Agreements"; allow (read, write, search) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:03:10Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "cert manager: Remove Replication Agreements";allow (delete) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG o=ipaca 2019-01-17T11:03:10Z DEBUG nsslapd-backend: 2019-01-17T11:03:10Z DEBUG ipaca 2019-01-17T11:03:10Z DEBUG remove: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";)' from aci, current value [u'(targetattr=*)(version 3.0;acl "cert manager: Add Replication Agreements";allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "cert manager: Modify Replication Agreements"; allow (read, write, search) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "cert manager: Remove Replication Agreements";allow (delete) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)'] 2019-01-17T11:03:10Z DEBUG remove: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local";)' not in aci 2019-01-17T11:03:10Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)' from aci, current value [u'(targetattr=*)(version 3.0;acl "cert manager: Add Replication Agreements";allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "cert manager: Modify Replication Agreements"; allow (read, write, search) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "cert manager: Remove Replication Agreements";allow (delete) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)'] 2019-01-17T11:03:10Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)' not in aci 2019-01-17T11:03:10Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";)' from aci, current value [u'(targetattr=*)(version 3.0;acl "cert manager: Add Replication Agreements";allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "cert manager: Modify Replication Agreements"; allow (read, write, search) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "cert manager: Remove Replication Agreements";allow (delete) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)'] 2019-01-17T11:03:10Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";)' not in aci 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=o\=ipaca,cn=mapping tree,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-state: 2019-01-17T11:03:10Z DEBUG Backend 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsMappingTree 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr=*)(version 3.0;acl "cert manager: Add Replication Agreements";allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:03:10Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "cert manager: Modify Replication Agreements"; allow (read, write, search) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:03:10Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "cert manager: Remove Replication Agreements";allow (delete) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG o=ipaca 2019-01-17T11:03:10Z DEBUG nsslapd-backend: 2019-01-17T11:03:10Z DEBUG ipaca 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=config 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-betype: 2019-01-17T11:03:10Z DEBUG ldbm database 2019-01-17T11:03:10Z DEBUG nsslapd-nagle: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-referralmode: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:03:10Z DEBUG 64 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 500 2019-01-17T11:03:10Z DEBUG passwordMinAlphas: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-readonly: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordLegacyPolicy: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:03:10Z DEBUG allowed 2019-01-17T11:03:10Z DEBUG passwordMinUppers: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-plugin: 2019-01-17T11:03:10Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:03:10Z DEBUG 20971520 2019-01-17T11:03:10Z DEBUG nsslapd-timelimit: 2019-01-17T11:03:10Z DEBUG 3600 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinTokenLength: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordMinAge: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:03:10Z DEBUG 60 2019-01-17T11:03:10Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:03:10Z DEBUG 1024 2019-01-17T11:03:10Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordInHistory: 2019-01-17T11:03:10Z DEBUG 6 2019-01-17T11:03:10Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-conntablesize: 2019-01-17T11:03:10Z DEBUG 16384 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-saslpath: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG passwordMaxAge: 2019-01-17T11:03:10Z DEBUG 8640000 2019-01-17T11:03:10Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:03:10Z DEBUG gidNumber 2019-01-17T11:03:10Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG day 2019-01-17T11:03:10Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-csnlogging: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-tmpdir: 2019-01-17T11:03:10Z DEBUG /tmp 2019-01-17T11:03:10Z DEBUG passwordResetFailureCount: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-counters: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-svrtab: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-minssf: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-schemadir: 2019-01-17T11:03:10Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:03:10Z DEBUG nsslapd-localuser: 2019-01-17T11:03:10Z DEBUG dirsrv 2019-01-17T11:03:10Z DEBUG nsslapd-security: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordChange: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-port 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:03:10Z DEBUG passwordMaxFailure: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:03:10Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:03:10Z DEBUG 128 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:03:10Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-rootdn: 2019-01-17T11:03:10Z DEBUG cn=Directory Manager 2019-01-17T11:03:10Z DEBUG nsslapd-ldifdir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:03:10Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordMustChange: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordExp: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-logging-backend: 2019-01-17T11:03:10Z DEBUG dirsrv-log 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:10Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:03:10Z DEBUG cn=Directory Manager 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinLength: 2019-01-17T11:03:10Z DEBUG 8 2019-01-17T11:03:10Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-idletimeout: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-securePort: 2019-01-17T11:03:10Z DEBUG 636 2019-01-17T11:03:10Z DEBUG nsslapd-snmp-index: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG config 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapdConfig 2019-01-17T11:03:10Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordSendExpiringTime: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-hash-filters: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:03:10Z DEBUG next 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-listenhost: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordCheckSyntax: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordGraceLimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG passwordWarning: 2019-01-17T11:03:10Z DEBUG 86400 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-instancedir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-config: 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-versionstring: 2019-01-17T11:03:10Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:03:10Z DEBUG 256 2019-01-17T11:03:10Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:03:10Z DEBUG SSHA512 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordLockout: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-lockdir: 2019-01-17T11:03:10Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-certdir: 2019-01-17T11:03:10Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 10 2019-01-17T11:03:10Z DEBUG nsslapd-backendconfig: 2019-01-17T11:03:10Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-threadnumber: 2019-01-17T11:03:10Z DEBUG 24 2019-01-17T11:03:10Z DEBUG nsslapd-schemamod: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-localhost: 2019-01-17T11:03:10Z DEBUG centos75.local 2019-01-17T11:03:10Z DEBUG nsslapd-bakdir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:03:10Z DEBUG passwordMin8bit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:03:10Z DEBUG uidNumber 2019-01-17T11:03:10Z DEBUG nsslapd-validate-cert: 2019-01-17T11:03:10Z DEBUG warn 2019-01-17T11:03:10Z DEBUG passwordMinCategories: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG passwordMinLowers: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordAdminDN: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordMinSpecials: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-lastmod: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:03:10Z DEBUG 40 2019-01-17T11:03:10Z DEBUG passwordMaxRepeats: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:03:10Z DEBUG -1 2019-01-17T11:03:10Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG nsslapd-result-tweak: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG passwordUnlock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-schemacheck: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-maxbersize: 2019-01-17T11:03:10Z DEBUG 209715200 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:03:10Z DEBUG dc=example,dc=com 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-localssf: 2019-01-17T11:03:10Z DEBUG 71 2019-01-17T11:03:10Z DEBUG nsslapd-sizelimit: 2019-01-17T11:03:10Z DEBUG 2000 2019-01-17T11:03:10Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG passwordLockoutDuration: 2019-01-17T11:03:10Z DEBUG 3600 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-port: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:03:10Z DEBUG cn=schema 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG cn=monitor 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-rootpw: 2019-01-17T11:03:10Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:03:10Z DEBUG 300000 2019-01-17T11:03:10Z DEBUG nsslapd-workingdir: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-rundir: 2019-01-17T11:03:10Z DEBUG /var/run/dirsrv 2019-01-17T11:03:10Z DEBUG nsslapd-schemareplace: 2019-01-17T11:03:10Z DEBUG replication-only 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:03:10Z DEBUG 16384 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:03:10Z DEBUG 10000 2019-01-17T11:03:10Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinDigits: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG passwordStorageScheme: 2019-01-17T11:03:10Z DEBUG SSHA512 2019-01-17T11:03:10Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG remove: '(targetattr != aci)(version 3.0; aci "replica admins read access"; allow (read, search, compare) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)' from aci, current value [u'(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";)', u'(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:10Z DEBUG remove: '(targetattr != aci)(version 3.0; aci "replica admins read access"; allow (read, search, compare) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local";)' not in aci 2019-01-17T11:03:10Z DEBUG remove: '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:System: Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Replication Agreements,cn=permissions,cn=pbac,dc=local";)' from aci, current value [u'(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";)', u'(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:10Z DEBUG remove: '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:System: Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Replication Agreements,cn=permissions,cn=pbac,dc=local";)' not in aci 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-betype: 2019-01-17T11:03:10Z DEBUG ldbm database 2019-01-17T11:03:10Z DEBUG nsslapd-nagle: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-referralmode: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:03:10Z DEBUG 64 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 500 2019-01-17T11:03:10Z DEBUG passwordMinAlphas: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-readonly: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordLegacyPolicy: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:03:10Z DEBUG allowed 2019-01-17T11:03:10Z DEBUG passwordMinUppers: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-plugin: 2019-01-17T11:03:10Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:03:10Z DEBUG 20971520 2019-01-17T11:03:10Z DEBUG nsslapd-timelimit: 2019-01-17T11:03:10Z DEBUG 3600 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinTokenLength: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordMinAge: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:03:10Z DEBUG 60 2019-01-17T11:03:10Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:03:10Z DEBUG 1024 2019-01-17T11:03:10Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordInHistory: 2019-01-17T11:03:10Z DEBUG 6 2019-01-17T11:03:10Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-conntablesize: 2019-01-17T11:03:10Z DEBUG 16384 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-saslpath: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG passwordMaxAge: 2019-01-17T11:03:10Z DEBUG 8640000 2019-01-17T11:03:10Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:03:10Z DEBUG gidNumber 2019-01-17T11:03:10Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG day 2019-01-17T11:03:10Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-csnlogging: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-tmpdir: 2019-01-17T11:03:10Z DEBUG /tmp 2019-01-17T11:03:10Z DEBUG passwordResetFailureCount: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-counters: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-svrtab: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-minssf: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-schemadir: 2019-01-17T11:03:10Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:03:10Z DEBUG nsslapd-localuser: 2019-01-17T11:03:10Z DEBUG dirsrv 2019-01-17T11:03:10Z DEBUG nsslapd-security: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordChange: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-port 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:03:10Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:03:10Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:03:10Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:03:10Z DEBUG passwordMaxFailure: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:03:10Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:03:10Z DEBUG 128 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:03:10Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-rootdn: 2019-01-17T11:03:10Z DEBUG cn=Directory Manager 2019-01-17T11:03:10Z DEBUG nsslapd-ldifdir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:03:10Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordMustChange: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordExp: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-logging-backend: 2019-01-17T11:03:10Z DEBUG dirsrv-log 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:10Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:03:10Z DEBUG cn=Directory Manager 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinLength: 2019-01-17T11:03:10Z DEBUG 8 2019-01-17T11:03:10Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-idletimeout: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:03:10Z DEBUG week 2019-01-17T11:03:10Z DEBUG nsslapd-securePort: 2019-01-17T11:03:10Z DEBUG 636 2019-01-17T11:03:10Z DEBUG nsslapd-snmp-index: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG config 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG extensibleObject 2019-01-17T11:03:10Z DEBUG nsslapdConfig 2019-01-17T11:03:10Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordSendExpiringTime: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-hash-filters: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:03:10Z DEBUG next 2019-01-17T11:03:10Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:03:10Z DEBUG -10 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-listenhost: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordCheckSyntax: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordGraceLimit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG passwordWarning: 2019-01-17T11:03:10Z DEBUG 86400 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-instancedir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-config: 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-versionstring: 2019-01-17T11:03:10Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:03:10Z DEBUG 256 2019-01-17T11:03:10Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:03:10Z DEBUG SSHA512 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG passwordLockout: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-lockdir: 2019-01-17T11:03:10Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-certdir: 2019-01-17T11:03:10Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 10 2019-01-17T11:03:10Z DEBUG nsslapd-backendconfig: 2019-01-17T11:03:10Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-threadnumber: 2019-01-17T11:03:10Z DEBUG 24 2019-01-17T11:03:10Z DEBUG nsslapd-schemamod: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-localhost: 2019-01-17T11:03:10Z DEBUG centos75.local 2019-01-17T11:03:10Z DEBUG nsslapd-bakdir: 2019-01-17T11:03:10Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:03:10Z DEBUG passwordMin8bit: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:03:10Z DEBUG uidNumber 2019-01-17T11:03:10Z DEBUG nsslapd-validate-cert: 2019-01-17T11:03:10Z DEBUG warn 2019-01-17T11:03:10Z DEBUG passwordMinCategories: 2019-01-17T11:03:10Z DEBUG 3 2019-01-17T11:03:10Z DEBUG passwordMinLowers: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordAdminDN: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordMinSpecials: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-lastmod: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:03:10Z DEBUG 40 2019-01-17T11:03:10Z DEBUG passwordMaxRepeats: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:03:10Z DEBUG -1 2019-01-17T11:03:10Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:03:10Z DEBUG none 2019-01-17T11:03:10Z DEBUG nsslapd-result-tweak: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:03:10Z DEBUG month 2019-01-17T11:03:10Z DEBUG passwordUnlock: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-schemacheck: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-maxbersize: 2019-01-17T11:03:10Z DEBUG 209715200 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:03:10Z DEBUG dc=example,dc=com 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-localssf: 2019-01-17T11:03:10Z DEBUG 71 2019-01-17T11:03:10Z DEBUG nsslapd-sizelimit: 2019-01-17T11:03:10Z DEBUG 2000 2019-01-17T11:03:10Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:03:10Z DEBUG dc=local 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:03:10Z DEBUG 2097152 2019-01-17T11:03:10Z DEBUG passwordLockoutDuration: 2019-01-17T11:03:10Z DEBUG 3600 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-port: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:03:10Z DEBUG 100 2019-01-17T11:03:10Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:03:10Z DEBUG cn=schema 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG cn=monitor 2019-01-17T11:03:10Z DEBUG cn=config 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:03:10Z DEBUG 1 2019-01-17T11:03:10Z DEBUG nsslapd-auditlog: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:03:10Z DEBUG 600 2019-01-17T11:03:10Z DEBUG nsslapd-rootpw: 2019-01-17T11:03:10Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:03:10Z DEBUG 300000 2019-01-17T11:03:10Z DEBUG nsslapd-workingdir: 2019-01-17T11:03:10Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:03:10Z DEBUG 2019-01-17T11:03:10Z DEBUG nsslapd-rundir: 2019-01-17T11:03:10Z DEBUG /var/run/dirsrv 2019-01-17T11:03:10Z DEBUG nsslapd-schemareplace: 2019-01-17T11:03:10Z DEBUG replication-only 2019-01-17T11:03:10Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:03:10Z DEBUG 16384 2019-01-17T11:03:10Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:03:10Z DEBUG 10000 2019-01-17T11:03:10Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:03:10Z DEBUG off 2019-01-17T11:03:10Z DEBUG passwordMinDigits: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:03:10Z DEBUG 5 2019-01-17T11:03:10Z DEBUG passwordStorageScheme: 2019-01-17T11:03:10Z DEBUG SSHA512 2019-01-17T11:03:10Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:03:10Z DEBUG on 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG domain 2019-01-17T11:03:10Z DEBUG pilotObject 2019-01-17T11:03:10Z DEBUG info: 2019-01-17T11:03:10Z DEBUG IPA V2.0 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG dc: 2019-01-17T11:03:10Z DEBUG local 2019-01-17T11:03:10Z DEBUG remove: '(targetattr = "*")(target = "ldap:///cn=*,cn=roles,cn=accounts,dc=local")(version 3.0; acl "No anonymous access to roles"; deny (read,search,compare) userdn != "ldap:///all";)' from aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG remove: '(targetattr = "*")(target = "ldap:///cn=*,cn=roles,cn=accounts,dc=local")(version 3.0; acl "No anonymous access to roles"; deny (read,search,compare) userdn != "ldap:///all";)' not in aci 2019-01-17T11:03:10Z DEBUG remove: '(targetattr = "memberOf || memberHost || memberUser")(version 3.0; acl "No anonymous access to member information"; deny (read,search,compare) userdn != "ldap:///all";)' from aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG remove: '(targetattr = "memberOf || memberHost || memberUser")(version 3.0; acl "No anonymous access to member information"; deny (read,search,compare) userdn != "ldap:///all";)' not in aci 2019-01-17T11:03:10Z DEBUG remove: '(targetattr = "*")(target = "ldap:///cn=*,ou=SUDOers,dc=local")(version 3.0; acl "No anonymous access to sudo"; deny (read,search,compare) userdn != "ldap:///all";)' from aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG remove: '(targetattr = "*")(target = "ldap:///cn=*,ou=SUDOers,dc=local")(version 3.0; acl "No anonymous access to sudo"; deny (read,search,compare) userdn != "ldap:///all";)' not in aci 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG domain 2019-01-17T11:03:10Z DEBUG pilotObject 2019-01-17T11:03:10Z DEBUG info: 2019-01-17T11:03:10Z DEBUG IPA V2.0 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG dc: 2019-01-17T11:03:10Z DEBUG local 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=hbac,dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=hbac,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG hbac 2019-01-17T11:03:10Z DEBUG remove: '(targetattr = "*")(version 3.0; acl "No anonymous access to hbac"; deny (read,search,compare) userdn != "ldap:///all";)' from aci, current value [] 2019-01-17T11:03:10Z DEBUG remove: '(targetattr = "*")(version 3.0; acl "No anonymous access to hbac"; deny (read,search,compare) userdn != "ldap:///all";)' not in aci 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=hbac,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG hbac 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=sudo,dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=sudo,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG sudo 2019-01-17T11:03:10Z DEBUG remove: '(targetattr = "*")(version 3.0; acl "No anonymous access to sudo"; deny (read,search,compare) userdn != "ldap:///all";)' from aci, current value [] 2019-01-17T11:03:10Z DEBUG remove: '(targetattr = "*")(version 3.0; acl "No anonymous access to sudo"; deny (read,search,compare) userdn != "ldap:///all";)' not in aci 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=sudo,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG sudo 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=accounts,dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=accounts,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";) 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG accounts 2019-01-17T11:03:10Z DEBUG add: '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)' to aci, current value [u'(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)'] 2019-01-17T11:03:10Z DEBUG add: '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)' to aci, current value [u'(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2019-01-17T11:03:10Z DEBUG add: '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)' to aci, current value [u'(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)'] 2019-01-17T11:03:10Z DEBUG add: '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)' to aci, current value [u'(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)'] 2019-01-17T11:03:10Z DEBUG add: '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)' to aci, current value [u'(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)'] 2019-01-17T11:03:10Z DEBUG add: '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' to aci, current value [u'(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG add: '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)' to aci, current value [u'(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=accounts,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";) 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG accounts 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG domain 2019-01-17T11:03:10Z DEBUG pilotObject 2019-01-17T11:03:10Z DEBUG info: 2019-01-17T11:03:10Z DEBUG IPA V2.0 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG dc: 2019-01-17T11:03:10Z DEBUG local 2019-01-17T11:03:10Z DEBUG add: '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG domain 2019-01-17T11:03:10Z DEBUG pilotObject 2019-01-17T11:03:10Z DEBUG info: 2019-01-17T11:03:10Z DEBUG IPA V2.0 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2019-01-17T11:03:10Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:10Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:10Z DEBUG dc: 2019-01-17T11:03:10Z DEBUG local 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=services,cn=accounts,dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=services,cn=accounts,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=local")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG services 2019-01-17T11:03:10Z DEBUG remove: '(target = "ldap:///krbprincipalname=*/($dn)@LOCAL,cn=services,cn=accounts,dc=local")(targetfilter = "(objectClass=ipaKrbPrincipal)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)' from aci, current value [u'(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=local")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)'] 2019-01-17T11:03:10Z DEBUG remove: '(target = "ldap:///krbprincipalname=*/($dn)@LOCAL,cn=services,cn=accounts,dc=local")(targetfilter = "(objectClass=ipaKrbPrincipal)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)' not in aci 2019-01-17T11:03:10Z DEBUG add: '(target = "ldap:///krbprincipalname=*/($dn)@LOCAL,cn=services,cn=accounts,dc=local")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)' to aci, current value [u'(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=local")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=local")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', u'(target = "ldap:///krbprincipalname=*/($dn)@LOCAL,cn=services,cn=accounts,dc=local")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG add: '(target = "ldap:///krbprincipalname=*/($dn)@LOCAL,cn=services,cn=accounts,dc=local")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)' to aci, current value [u'(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=local")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', u'(target = "ldap:///krbprincipalname=*/($dn)@LOCAL,cn=services,cn=accounts,dc=local")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=local")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', u'(target = "ldap:///krbprincipalname=*/($dn)@LOCAL,cn=services,cn=accounts,dc=local")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///krbprincipalname=*/($dn)@LOCAL,cn=services,cn=accounts,dc=local")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=services,cn=accounts,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=local")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///krbprincipalname=*/($dn)@LOCAL,cn=services,cn=accounts,dc=local")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///krbprincipalname=*/($dn)@LOCAL,cn=services,cn=accounts,dc=local")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG services 2019-01-17T11:03:10Z DEBUG [(0, u'aci', [u'(target = "ldap:///krbprincipalname=*/($dn)@LOCAL,cn=services,cn=accounts,dc=local")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///krbprincipalname=*/($dn)@LOCAL,cn=services,cn=accounts,dc=local")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)'])] 2019-01-17T11:03:10Z DEBUG Updated 1 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=ranges,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=ranges,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG ranges 2019-01-17T11:03:10Z DEBUG add: '(target = "ldap:///cn=*,cn=ranges,cn=etc,dc=local")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@LOCAL,cn=services,cn=accounts,dc=local" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)' to aci, current value [] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(target = "ldap:///cn=*,cn=ranges,cn=etc,dc=local")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@LOCAL,cn=services,cn=accounts,dc=local" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=ranges,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=*,cn=ranges,cn=etc,dc=local")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@LOCAL,cn=services,cn=accounts,dc=local" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";) 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG ranges 2019-01-17T11:03:10Z DEBUG [(2, u'aci', [u'(target = "ldap:///cn=*,cn=ranges,cn=etc,dc=local")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@LOCAL,cn=services,cn=accounts,dc=local" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)'])] 2019-01-17T11:03:10Z DEBUG Updated 1 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=local")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG sysaccounts 2019-01-17T11:03:10Z DEBUG add: '(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=local")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)' to aci, current value [u'(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=local")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=local")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=local")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=local")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=local")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG sysaccounts 2019-01-17T11:03:10Z DEBUG [(0, u'aci', [u'(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=local")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)'])] 2019-01-17T11:03:10Z DEBUG Updated 1 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaGuiConfig)")(targetattr != "aci")(version 3.0;acl "Admins can change GUI config"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG etc 2019-01-17T11:03:10Z DEBUG add: '(target = "ldap:///cn=replication,cn=etc,dc=local")(targetattr = "nsDS5ReplicaId")(version 3.0; acl "IPA server hosts can change replica ID"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)' to aci, current value [u'(targetfilter = "(objectClass=ipaGuiConfig)")(targetattr != "aci")(version 3.0;acl "Admins can change GUI config"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetfilter = "(objectClass=ipaGuiConfig)")(targetattr != "aci")(version 3.0;acl "Admins can change GUI config"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(target = "ldap:///cn=replication,cn=etc,dc=local")(targetattr = "nsDS5ReplicaId")(version 3.0; acl "IPA server hosts can change replica ID"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetfilter = "(objectClass=ipaGuiConfig)")(targetattr != "aci")(version 3.0;acl "Admins can change GUI config"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=replication,cn=etc,dc=local")(targetattr = "nsDS5ReplicaId")(version 3.0; acl "IPA server hosts can change replica ID"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG etc 2019-01-17T11:03:10Z DEBUG [(0, u'aci', [u'(target = "ldap:///cn=replication,cn=etc,dc=local")(targetattr = "nsDS5ReplicaId")(version 3.0; acl "IPA server hosts can change replica ID"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)'])] 2019-01-17T11:03:10Z DEBUG Updated 1 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=ipa,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=ipa,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG ipa 2019-01-17T11:03:10Z DEBUG add: '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)' to aci, current value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG add: '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)' to aci, current value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=ipa,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG ipa 2019-01-17T11:03:10Z DEBUG [(0, u'aci', [u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)'])] 2019-01-17T11:03:10Z DEBUG Updated 1 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: cn=ipa,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=ipa,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG ipa 2019-01-17T11:03:10Z DEBUG add: '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)' to aci, current value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG add: '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)' to aci, current value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG add: '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LOCAL,cn=services,cn=accounts,dc=local";)' to aci, current value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG add: updated value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LOCAL,cn=services,cn=accounts,dc=local";)'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=ipa,cn=etc,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LOCAL,cn=services,cn=accounts,dc=local";) 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG ipa 2019-01-17T11:03:10Z DEBUG [(0, u'aci', [u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LOCAL,cn=services,cn=accounts,dc=local";)'])] 2019-01-17T11:03:10Z DEBUG Updated 1 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Updating existing entry: krbPrincipalName=WELLKNOWN/ANONYMOUS@LOCAL,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: krbPrincipalName=WELLKNOWN/ANONYMOUS@LOCAL,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:03:10Z DEBUG krbPrincipalKey: 2019-01-17T11:03:10Z DEBUG XXXXXXXX 2019-01-17T11:03:10Z DEBUG krbCanonicalName: 2019-01-17T11:03:10Z DEBUG WELLKNOWN/ANONYMOUS@LOCAL 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG krbprincipal 2019-01-17T11:03:10Z DEBUG krbprincipalaux 2019-01-17T11:03:10Z DEBUG krbTicketPolicyAux 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG ipaAllowedOperations 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2019-01-17T11:03:10Z DEBUG ipaAllowedToPerform;read_keys: 2019-01-17T11:03:10Z DEBUG cn=ipaservers,cn=hostgroups,cn=accounts,dc=local 2019-01-17T11:03:10Z DEBUG krbExtraData: 2019-01-17T11:03:10Z DEBUG rZ@\root/admin@LOCAL 2019-01-17T11:03:10Z DEBUG krbPrincipalName: 2019-01-17T11:03:10Z DEBUG WELLKNOWN/ANONYMOUS@LOCAL 2019-01-17T11:03:10Z DEBUG krbLastPwdChange: 2019-01-17T11:03:10Z DEBUG 20190117103530Z 2019-01-17T11:03:10Z DEBUG addifexist: 'ipaAllowedOperations' to objectclass, current value [u'krbprincipal', u'krbprincipalaux', u'krbTicketPolicyAux', u'top', u'ipaAllowedOperations'] 2019-01-17T11:03:10Z DEBUG addifexist: set objectclass to [u'krbprincipal', u'krbprincipalaux', u'krbTicketPolicyAux', u'top', u'ipaAllowedOperations', u'ipaAllowedOperations'] 2019-01-17T11:03:10Z DEBUG addifexist: '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)' to aci, current value [u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2019-01-17T11:03:10Z DEBUG addifexist: set aci to [u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2019-01-17T11:03:10Z DEBUG addifexist: 'cn=ipaservers,cn=hostgroups,cn=accounts,dc=local' to ipaAllowedToPerform;read_keys, current value [u'cn=ipaservers,cn=hostgroups,cn=accounts,dc=local'] 2019-01-17T11:03:10Z DEBUG addifexist: set ipaAllowedToPerform;read_keys to [u'cn=ipaservers,cn=hostgroups,cn=accounts,dc=local', u'cn=ipaservers,cn=hostgroups,cn=accounts,dc=local'] 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: krbPrincipalName=WELLKNOWN/ANONYMOUS@LOCAL,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:03:10Z DEBUG krbPrincipalKey: 2019-01-17T11:03:10Z DEBUG XXXXXXXX 2019-01-17T11:03:10Z DEBUG krbCanonicalName: 2019-01-17T11:03:10Z DEBUG WELLKNOWN/ANONYMOUS@LOCAL 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG krbprincipal 2019-01-17T11:03:10Z DEBUG krbprincipalaux 2019-01-17T11:03:10Z DEBUG krbTicketPolicyAux 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG ipaAllowedOperations 2019-01-17T11:03:10Z DEBUG ipaAllowedOperations 2019-01-17T11:03:10Z DEBUG aci: 2019-01-17T11:03:10Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2019-01-17T11:03:10Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2019-01-17T11:03:10Z DEBUG ipaAllowedToPerform;read_keys: 2019-01-17T11:03:10Z DEBUG cn=ipaservers,cn=hostgroups,cn=accounts,dc=local 2019-01-17T11:03:10Z DEBUG cn=ipaservers,cn=hostgroups,cn=accounts,dc=local 2019-01-17T11:03:10Z DEBUG krbExtraData: 2019-01-17T11:03:10Z DEBUG rZ@\root/admin@LOCAL 2019-01-17T11:03:10Z DEBUG krbPrincipalName: 2019-01-17T11:03:10Z DEBUG WELLKNOWN/ANONYMOUS@LOCAL 2019-01-17T11:03:10Z DEBUG krbLastPwdChange: 2019-01-17T11:03:10Z DEBUG 20190117103530Z 2019-01-17T11:03:10Z DEBUG [] 2019-01-17T11:03:10Z DEBUG Updated 0 2019-01-17T11:03:10Z DEBUG Done 2019-01-17T11:03:10Z DEBUG Parsing update file '/usr/share/ipa/updates/20-default_password_policy.update' 2019-01-17T11:03:10Z DEBUG New entry: cn=Default Host Password Policy,cn=computers,cn=accounts,dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=Default Host Password Policy,cn=computers,cn=accounts,dc=local 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG Default Host Password Policy 2019-01-17T11:03:10Z DEBUG krbPwdHistoryLength: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG krbPwdPolicy 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG krbPwdMinDiffChars: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG krbPwdMinLength: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG krbPwdLockoutDuration: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG krbPwdMaxFailure: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG krbMaxPwdLife: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG krbPwdFailureCountInterval: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG krbMinPwdLife: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=Default Host Password Policy,cn=computers,cn=accounts,dc=local 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG Default Host Password Policy 2019-01-17T11:03:10Z DEBUG krbPwdHistoryLength: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG krbPwdPolicy 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG krbPwdMinDiffChars: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG krbPwdMinLength: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG krbPwdLockoutDuration: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG krbPwdMaxFailure: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG krbMaxPwdLife: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG krbPwdFailureCountInterval: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG krbMinPwdLife: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG New entry: cn=Default Service Password Policy,cn=services,cn=accounts,dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=Default Service Password Policy,cn=services,cn=accounts,dc=local 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG Default Service Password Policy 2019-01-17T11:03:10Z DEBUG krbPwdHistoryLength: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG krbPwdPolicy 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG krbPwdMinDiffChars: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG krbPwdMinLength: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG krbPwdLockoutDuration: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG krbPwdMaxFailure: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG krbMaxPwdLife: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG krbPwdFailureCountInterval: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG krbMinPwdLife: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=Default Service Password Policy,cn=services,cn=accounts,dc=local 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG Default Service Password Policy 2019-01-17T11:03:10Z DEBUG krbPwdHistoryLength: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG krbPwdPolicy 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG krbPwdMinDiffChars: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG krbPwdMinLength: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG krbPwdLockoutDuration: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG krbPwdMaxFailure: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG krbMaxPwdLife: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG krbPwdFailureCountInterval: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG krbMinPwdLife: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG New entry: cn=Kerberos Service Password Policy,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=Kerberos Service Password Policy,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG Kerberos Service Password Policy 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=Kerberos Service Password Policy,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG Kerberos Service Password Policy 2019-01-17T11:03:10Z DEBUG New entry: cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG Default Kerberos Service Password Policy 2019-01-17T11:03:10Z DEBUG krbPwdHistoryLength: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG krbPwdPolicy 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG krbPwdMinDiffChars: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG krbPwdMinLength: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG krbPwdLockoutDuration: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG krbPwdMaxFailure: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG krbMaxPwdLife: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG krbPwdFailureCountInterval: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG krbMinPwdLife: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG Default Kerberos Service Password Policy 2019-01-17T11:03:10Z DEBUG krbPwdHistoryLength: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG objectClass: 2019-01-17T11:03:10Z DEBUG krbPwdPolicy 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG krbPwdMinDiffChars: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG krbPwdMinLength: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG krbPwdLockoutDuration: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG krbPwdMaxFailure: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG krbMaxPwdLife: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG krbPwdFailureCountInterval: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG krbMinPwdLife: 2019-01-17T11:03:10Z DEBUG 0 2019-01-17T11:03:10Z DEBUG New entry: cn=cosTemplates,cn=computers,cn=accounts,dc=local 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Initial value 2019-01-17T11:03:10Z DEBUG dn: cn=cosTemplates,cn=computers,cn=accounts,dc=local 2019-01-17T11:03:10Z DEBUG objectclass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG cosTemplates 2019-01-17T11:03:10Z DEBUG --------------------------------------------- 2019-01-17T11:03:10Z DEBUG Final value after applying updates 2019-01-17T11:03:10Z DEBUG dn: cn=cosTemplates,cn=computers,cn=accounts,dc=local 2019-01-17T11:03:10Z DEBUG objectclass: 2019-01-17T11:03:10Z DEBUG top 2019-01-17T11:03:10Z DEBUG nsContainer 2019-01-17T11:03:10Z DEBUG cn: 2019-01-17T11:03:10Z DEBUG cosTemplates 2019-01-17T11:03:11Z DEBUG New entry: cn=Default Password Policy,cn=cosTemplates,cn=computers,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=computers,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG objectclass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG cosTemplate 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG krbContainer 2019-01-17T11:03:11Z DEBUG krbPwdPolicyReference: 2019-01-17T11:03:11Z DEBUG cn=Default Host Password Policy,cn=computers,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG cosPriority: 2019-01-17T11:03:11Z DEBUG 10000000000 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Default Password Policy 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=computers,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG objectclass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG cosTemplate 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG krbContainer 2019-01-17T11:03:11Z DEBUG krbPwdPolicyReference: 2019-01-17T11:03:11Z DEBUG cn=Default Host Password Policy,cn=computers,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG cosPriority: 2019-01-17T11:03:11Z DEBUG 10000000000 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Default Password Policy 2019-01-17T11:03:11Z DEBUG New entry: cn=Default Password Policy,cn=computers,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=Default Password Policy,cn=computers,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG ldapsubentry 2019-01-17T11:03:11Z DEBUG cosSuperDefinition 2019-01-17T11:03:11Z DEBUG cosPointerDefinition 2019-01-17T11:03:11Z DEBUG cosTemplateDn: 2019-01-17T11:03:11Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=computers,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG description: 2019-01-17T11:03:11Z DEBUG Default Password Policy for Hosts 2019-01-17T11:03:11Z DEBUG cosAttribute: 2019-01-17T11:03:11Z DEBUG krbPwdPolicyReference default 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=Default Password Policy,cn=computers,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG ldapsubentry 2019-01-17T11:03:11Z DEBUG cosSuperDefinition 2019-01-17T11:03:11Z DEBUG cosPointerDefinition 2019-01-17T11:03:11Z DEBUG cosTemplateDn: 2019-01-17T11:03:11Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=computers,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG description: 2019-01-17T11:03:11Z DEBUG Default Password Policy for Hosts 2019-01-17T11:03:11Z DEBUG cosAttribute: 2019-01-17T11:03:11Z DEBUG krbPwdPolicyReference default 2019-01-17T11:03:11Z DEBUG New entry: cn=cosTemplates,cn=services,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=cosTemplates,cn=services,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG objectclass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG cosTemplates 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=cosTemplates,cn=services,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG objectclass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG cosTemplates 2019-01-17T11:03:11Z DEBUG New entry: cn=Default Password Policy,cn=cosTemplates,cn=services,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=services,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG objectclass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG cosTemplate 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG krbContainer 2019-01-17T11:03:11Z DEBUG krbPwdPolicyReference: 2019-01-17T11:03:11Z DEBUG cn=Default Service Password Policy,cn=services,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG cosPriority: 2019-01-17T11:03:11Z DEBUG 10000000000 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Default Password Policy 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=services,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG objectclass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG cosTemplate 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG krbContainer 2019-01-17T11:03:11Z DEBUG krbPwdPolicyReference: 2019-01-17T11:03:11Z DEBUG cn=Default Service Password Policy,cn=services,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG cosPriority: 2019-01-17T11:03:11Z DEBUG 10000000000 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Default Password Policy 2019-01-17T11:03:11Z DEBUG New entry: cn=Default Password Policy,cn=services,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=Default Password Policy,cn=services,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG ldapsubentry 2019-01-17T11:03:11Z DEBUG cosSuperDefinition 2019-01-17T11:03:11Z DEBUG cosPointerDefinition 2019-01-17T11:03:11Z DEBUG cosTemplateDn: 2019-01-17T11:03:11Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=services,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG description: 2019-01-17T11:03:11Z DEBUG Default Password Policy for Services 2019-01-17T11:03:11Z DEBUG cosAttribute: 2019-01-17T11:03:11Z DEBUG krbPwdPolicyReference default 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=Default Password Policy,cn=services,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG ldapsubentry 2019-01-17T11:03:11Z DEBUG cosSuperDefinition 2019-01-17T11:03:11Z DEBUG cosPointerDefinition 2019-01-17T11:03:11Z DEBUG cosTemplateDn: 2019-01-17T11:03:11Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=services,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG description: 2019-01-17T11:03:11Z DEBUG Default Password Policy for Services 2019-01-17T11:03:11Z DEBUG cosAttribute: 2019-01-17T11:03:11Z DEBUG krbPwdPolicyReference default 2019-01-17T11:03:11Z DEBUG New entry: cn=cosTemplates,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=cosTemplates,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:03:11Z DEBUG objectclass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG cosTemplates 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=cosTemplates,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:03:11Z DEBUG objectclass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG cosTemplates 2019-01-17T11:03:11Z DEBUG New entry: cn=Default Password Policy,cn=cosTemplates,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:03:11Z DEBUG objectclass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG cosTemplate 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG krbContainer 2019-01-17T11:03:11Z DEBUG krbPwdPolicyReference: 2019-01-17T11:03:11Z DEBUG cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:03:11Z DEBUG cosPriority: 2019-01-17T11:03:11Z DEBUG 10000000000 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Default Password Policy 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:03:11Z DEBUG objectclass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG cosTemplate 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG krbContainer 2019-01-17T11:03:11Z DEBUG krbPwdPolicyReference: 2019-01-17T11:03:11Z DEBUG cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:03:11Z DEBUG cosPriority: 2019-01-17T11:03:11Z DEBUG 10000000000 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Default Password Policy 2019-01-17T11:03:11Z DEBUG New entry: cn=Default Password Policy,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=Default Password Policy,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG ldapsubentry 2019-01-17T11:03:11Z DEBUG cosSuperDefinition 2019-01-17T11:03:11Z DEBUG cosPointerDefinition 2019-01-17T11:03:11Z DEBUG cosTemplateDn: 2019-01-17T11:03:11Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:03:11Z DEBUG description: 2019-01-17T11:03:11Z DEBUG Default Password Policy for Kerberos Services 2019-01-17T11:03:11Z DEBUG cosAttribute: 2019-01-17T11:03:11Z DEBUG krbPwdPolicyReference default 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=Default Password Policy,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG ldapsubentry 2019-01-17T11:03:11Z DEBUG cosSuperDefinition 2019-01-17T11:03:11Z DEBUG cosPointerDefinition 2019-01-17T11:03:11Z DEBUG cosTemplateDn: 2019-01-17T11:03:11Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:03:11Z DEBUG description: 2019-01-17T11:03:11Z DEBUG Default Password Policy for Kerberos Services 2019-01-17T11:03:11Z DEBUG cosAttribute: 2019-01-17T11:03:11Z DEBUG krbPwdPolicyReference default 2019-01-17T11:03:11Z DEBUG Parsing update file '/usr/share/ipa/updates/20-dna.update' 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=ipa-winsync,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=ipa-winsync,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipa-winsync 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG ipawinsynchomedirattr: 2019-01-17T11:03:11Z DEBUG ipaHomesRootDir 2019-01-17T11:03:11Z DEBUG ipawinsyncnewuserocattr: 2019-01-17T11:03:11Z DEBUG ipauserobjectclasses 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libipa_winsync 2019-01-17T11:03:11Z DEBUG ipawinsyncuserflatten: 2019-01-17T11:03:11Z DEBUG true 2019-01-17T11:03:11Z DEBUG ipawinsyncdefaultgroupfilter: 2019-01-17T11:03:11Z DEBUG (gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames) 2019-01-17T11:03:11Z DEBUG ipawinsyncforcesync: 2019-01-17T11:03:11Z DEBUG true 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG FreeIPA/1.0 2019-01-17T11:03:11Z DEBUG ipawinsyncrealmattr: 2019-01-17T11:03:11Z DEBUG cn 2019-01-17T11:03:11Z DEBUG ipawinsyncacctdisable: 2019-01-17T11:03:11Z DEBUG both 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG ipa_winsync_plugin_init 2019-01-17T11:03:11Z DEBUG ipawinsyncnewentryfilter: 2019-01-17T11:03:11Z DEBUG (cn=ipaConfig) 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG FreeIPA project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:03:11Z DEBUG 60 2019-01-17T11:03:11Z DEBUG ipawinsyncdefaultgroupattr: 2019-01-17T11:03:11Z DEBUG ipaDefaultPrimaryGroup 2019-01-17T11:03:11Z DEBUG ipawinsyncrealmfilter: 2019-01-17T11:03:11Z DEBUG (objectclass=krbRealmContainer) 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG preoperation 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG ipa winsync plugin 2019-01-17T11:03:11Z DEBUG ipawinsyncloginshellattr: 2019-01-17T11:03:11Z DEBUG ipaDefaultLoginShell 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG ipa-winsync-plugin 2019-01-17T11:03:11Z DEBUG ipawinsyncuserattr: 2019-01-17T11:03:11Z DEBUG uidNumber -1 2019-01-17T11:03:11Z DEBUG gidNumber -1 2019-01-17T11:03:11Z DEBUG remove: 'uidNumber 999' from ipaWinSyncUserAttr, current value [u'uidNumber -1', u'gidNumber -1'] 2019-01-17T11:03:11Z DEBUG remove: 'uidNumber 999' not in ipaWinSyncUserAttr 2019-01-17T11:03:11Z DEBUG remove: 'gidNumber 999' from ipaWinSyncUserAttr, current value [u'uidNumber -1', u'gidNumber -1'] 2019-01-17T11:03:11Z DEBUG remove: 'gidNumber 999' not in ipaWinSyncUserAttr 2019-01-17T11:03:11Z DEBUG add: 'uidNumber -1' to ipaWinSyncUserAttr, current value [u'uidNumber -1', u'gidNumber -1'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'gidNumber -1', u'uidNumber -1'] 2019-01-17T11:03:11Z DEBUG add: 'gidNumber -1' to ipaWinSyncUserAttr, current value [u'gidNumber -1', u'uidNumber -1'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'uidNumber -1', u'gidNumber -1'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=ipa-winsync,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipa-winsync 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG ipawinsynchomedirattr: 2019-01-17T11:03:11Z DEBUG ipaHomesRootDir 2019-01-17T11:03:11Z DEBUG ipawinsyncnewuserocattr: 2019-01-17T11:03:11Z DEBUG ipauserobjectclasses 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libipa_winsync 2019-01-17T11:03:11Z DEBUG ipawinsyncuserflatten: 2019-01-17T11:03:11Z DEBUG true 2019-01-17T11:03:11Z DEBUG ipawinsyncdefaultgroupfilter: 2019-01-17T11:03:11Z DEBUG (gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames) 2019-01-17T11:03:11Z DEBUG ipawinsyncforcesync: 2019-01-17T11:03:11Z DEBUG true 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG FreeIPA/1.0 2019-01-17T11:03:11Z DEBUG ipawinsyncrealmattr: 2019-01-17T11:03:11Z DEBUG cn 2019-01-17T11:03:11Z DEBUG ipawinsyncacctdisable: 2019-01-17T11:03:11Z DEBUG both 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG ipa_winsync_plugin_init 2019-01-17T11:03:11Z DEBUG ipawinsyncnewentryfilter: 2019-01-17T11:03:11Z DEBUG (cn=ipaConfig) 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG FreeIPA project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:03:11Z DEBUG 60 2019-01-17T11:03:11Z DEBUG ipawinsyncdefaultgroupattr: 2019-01-17T11:03:11Z DEBUG ipaDefaultPrimaryGroup 2019-01-17T11:03:11Z DEBUG ipawinsyncrealmfilter: 2019-01-17T11:03:11Z DEBUG (objectclass=krbRealmContainer) 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG preoperation 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG ipa winsync plugin 2019-01-17T11:03:11Z DEBUG ipawinsyncloginshellattr: 2019-01-17T11:03:11Z DEBUG ipaDefaultLoginShell 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG ipa-winsync-plugin 2019-01-17T11:03:11Z DEBUG ipawinsyncuserattr: 2019-01-17T11:03:11Z DEBUG uidNumber -1 2019-01-17T11:03:11Z DEBUG gidNumber -1 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Parsing update file '/usr/share/ipa/updates/20-enable_dirsrv_plugins.update' 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=7-bit check,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG NS7bitAttr 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG 7-bit check 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG NS7bitAttr_Init 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG Enforce 7-bit clean attribute values 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libattr-unique-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginarg0: 2019-01-17T11:03:11Z DEBUG uid 2019-01-17T11:03:11Z DEBUG nsslapd-pluginarg3: 2019-01-17T11:03:11Z DEBUG dc=local 2019-01-17T11:03:11Z DEBUG nsslapd-pluginarg2: 2019-01-17T11:03:11Z DEBUG , 2019-01-17T11:03:11Z DEBUG nsslapd-pluginarg1: 2019-01-17T11:03:11Z DEBUG mail 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG betxnpreoperation 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG replace: off not found, skipping 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG NS7bitAttr 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG 7-bit check 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG NS7bitAttr_Init 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG Enforce 7-bit clean attribute values 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libattr-unique-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginarg0: 2019-01-17T11:03:11Z DEBUG uid 2019-01-17T11:03:11Z DEBUG nsslapd-pluginarg3: 2019-01-17T11:03:11Z DEBUG dc=local 2019-01-17T11:03:11Z DEBUG nsslapd-pluginarg2: 2019-01-17T11:03:11Z DEBUG , 2019-01-17T11:03:11Z DEBUG nsslapd-pluginarg1: 2019-01-17T11:03:11Z DEBUG mail 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG betxnpreoperation 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=Account Usability Plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=Account Usability Plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG Account Usability Control 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Account Usability Plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG Account Usability Control plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libacctusability-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG preoperation 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG auc_init 2019-01-17T11:03:11Z DEBUG replace: off not found, skipping 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=Account Usability Plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG Account Usability Control 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Account Usability Plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG Account Usability Control plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libacctusability-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG preoperation 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG auc_init 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=ACL Plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=ACL Plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG acl 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ACL Plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG acl access check plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libacl-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG accesscontrol 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG acl_init 2019-01-17T11:03:11Z DEBUG replace: off not found, skipping 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=ACL Plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG acl 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ACL Plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG acl access check plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libacl-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG accesscontrol 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG acl_init 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=ACL preoperation,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=ACL preoperation,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG acl 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ACL preoperation 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG acl access check plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libacl-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG preoperation 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG acl_preopInit 2019-01-17T11:03:11Z DEBUG replace: off not found, skipping 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=ACL preoperation,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG acl 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ACL preoperation 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG acl access check plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libacl-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG preoperation 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG acl_preopInit 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=Auto Membership Plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG Auto Membership 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Auto Membership Plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG Auto Membership plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libautomember-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginConfigArea: 2019-01-17T11:03:11Z DEBUG cn=automember,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG betxnpreoperation 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG automember_init 2019-01-17T11:03:11Z DEBUG replace: off not found, skipping 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG Auto Membership 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Auto Membership Plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG Auto Membership plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libautomember-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginConfigArea: 2019-01-17T11:03:11Z DEBUG cn=automember,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG betxnpreoperation 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG automember_init 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=Bitwise Plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=Bitwise Plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG bitwise 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Bitwise Plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG bitwise match plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libbitwise-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG matchingRule 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG bitwise_init 2019-01-17T11:03:11Z DEBUG replace: off not found, skipping 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=Bitwise Plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG bitwise 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Bitwise Plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG bitwise match plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libbitwise-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG matchingRule 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG bitwise_init 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=chaining database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=chaining database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG chaining database 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG chaining database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG LDAP chaining backend database plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libchainingdb-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG chaining_back_init 2019-01-17T11:03:11Z DEBUG replace: off not found, skipping 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=chaining database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG chaining database 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG chaining database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG LDAP chaining backend database plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libchainingdb-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG chaining_back_init 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=Class of Service,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=Class of Service,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG cos 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Class of Service 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-named: 2019-01-17T11:03:11Z DEBUG State Change Plugin 2019-01-17T11:03:11Z DEBUG Views 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG class of service plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libcos-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG object 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG cos_init 2019-01-17T11:03:11Z DEBUG replace: off not found, skipping 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=Class of Service,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG cos 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Class of Service 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-named: 2019-01-17T11:03:11Z DEBUG State Change Plugin 2019-01-17T11:03:11Z DEBUG Views 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG class of service plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libcos-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG object 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG cos_init 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=deref,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=deref,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG Dereference 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG deref 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG Dereference plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libderef-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG preoperation 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG deref_init 2019-01-17T11:03:11Z DEBUG replace: off not found, skipping 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=deref,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG Dereference 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG deref 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG Dereference plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libderef-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG preoperation 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG deref_init 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=HTTP Client,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=HTTP Client,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG http-client 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG HTTP Client 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG HTTP Client plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libhttp-client-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG preoperation 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG http_client_init 2019-01-17T11:03:11Z DEBUG replace: off not found, skipping 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=HTTP Client,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG http-client 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG HTTP Client 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG HTTP Client plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libhttp-client-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG preoperation 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG http_client_init 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=Internationalization Plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=Internationalization Plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG orderingrule 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Internationalization Plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG internationalized ordering rule plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libcollation-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-pluginarg0: 2019-01-17T11:03:11Z DEBUG /etc/dirsrv/slapd-LOCAL/slapd-collations.conf 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG orderingRule_init 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG matchingRule 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG replace: off not found, skipping 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=Internationalization Plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG orderingrule 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Internationalization Plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG internationalized ordering rule plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libcollation-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-pluginarg0: 2019-01-17T11:03:11Z DEBUG /etc/dirsrv/slapd-LOCAL/slapd-collations.conf 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG orderingRule_init 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG matchingRule 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=Linked Attributes,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=Linked Attributes,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG Linked Attributes 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Linked Attributes 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG Linked Attributes plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG liblinkedattrs-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG betxnpreoperation 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG linked_attrs_init 2019-01-17T11:03:11Z DEBUG replace: off not found, skipping 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=Linked Attributes,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG Linked Attributes 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Linked Attributes 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG Linked Attributes plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG liblinkedattrs-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG betxnpreoperation 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG linked_attrs_init 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=Managed Entries,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG Managed Entries 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Managed Entries 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG Managed Entries plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libmanagedentries-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginConfigArea: 2019-01-17T11:03:11Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG betxnpreoperation 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG mep_init 2019-01-17T11:03:11Z DEBUG replace: off not found, skipping 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG Managed Entries 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Managed Entries 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG Managed Entries plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libmanagedentries-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginConfigArea: 2019-01-17T11:03:11Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG betxnpreoperation 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG mep_init 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=Multimaster Replication Plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=Multimaster Replication Plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Multimaster Replication Plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG replication_multimaster_plugin_init 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-named: 2019-01-17T11:03:11Z DEBUG ldbm database 2019-01-17T11:03:11Z DEBUG AES 2019-01-17T11:03:11Z DEBUG Class of Service 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG Multi-master Replication Plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libreplication-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG replication-multimaster 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG object 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG replace: off not found, skipping 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=Multimaster Replication Plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Multimaster Replication Plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG replication_multimaster_plugin_init 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-named: 2019-01-17T11:03:11Z DEBUG ldbm database 2019-01-17T11:03:11Z DEBUG AES 2019-01-17T11:03:11Z DEBUG Class of Service 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG Multi-master Replication Plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libreplication-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG replication-multimaster 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG object 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=Roles Plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=Roles Plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Roles Plugin 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-named: 2019-01-17T11:03:11Z DEBUG State Change Plugin 2019-01-17T11:03:11Z DEBUG Views 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG roles plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libroles-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG roles 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG roles_init 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG object 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG replace: off not found, skipping 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=Roles Plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Roles Plugin 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-named: 2019-01-17T11:03:11Z DEBUG State Change Plugin 2019-01-17T11:03:11Z DEBUG Views 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG roles plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libroles-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG roles 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG roles_init 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG object 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=Schema Reload,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=Schema Reload,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG schemareload 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Schema Reload 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG task plugin to reload schema files 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libschemareload-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG object 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG schemareload_init 2019-01-17T11:03:11Z DEBUG replace: off not found, skipping 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=Schema Reload,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG schemareload 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Schema Reload 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG task plugin to reload schema files 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libschemareload-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG object 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG schemareload_init 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=State Change Plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=State Change Plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG statechange 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG State Change Plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG state change notification service plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libstatechange-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG betxnpostoperation 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG statechange_init 2019-01-17T11:03:11Z DEBUG replace: off not found, skipping 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=State Change Plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG statechange 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG State Change Plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG state change notification service plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libstatechange-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG betxnpostoperation 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG statechange_init 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=Views,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=Views,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG views 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Views 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-named: 2019-01-17T11:03:11Z DEBUG State Change Plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG virtual directory information tree views plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libviews-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG object 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG views_init 2019-01-17T11:03:11Z DEBUG replace: off not found, skipping 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=Views,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG views 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Views 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-named: 2019-01-17T11:03:11Z DEBUG State Change Plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG virtual directory information tree views plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libviews-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG object 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG views_init 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=whoami,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=whoami,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG whoami-plugin 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG whoami 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG whoami extended operation plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libwhoami-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG extendedop 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG whoami_init 2019-01-17T11:03:11Z DEBUG replace: off not found, skipping 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=whoami,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG whoami-plugin 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG whoami 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG whoami extended operation plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libwhoami-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG extendedop 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG whoami_init 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Parsing update file '/usr/share/ipa/updates/20-host_nis_groups.update' 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG mepTemplateEntry 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG mepMappedAttr: 2019-01-17T11:03:11Z DEBUG cn: $cn 2019-01-17T11:03:11Z DEBUG memberHost: $dn 2019-01-17T11:03:11Z DEBUG description: ipaNetgroup $cn 2019-01-17T11:03:11Z DEBUG mepStaticAttr: 2019-01-17T11:03:11Z DEBUG ipaUniqueId: autogenerate 2019-01-17T11:03:11Z DEBUG objectclass: ipanisnetgroup 2019-01-17T11:03:11Z DEBUG objectclass: ipaobject 2019-01-17T11:03:11Z DEBUG nisDomainName: local 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG NGP HGP Template 2019-01-17T11:03:11Z DEBUG mepRDNAttr: 2019-01-17T11:03:11Z DEBUG cn 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG mepTemplateEntry 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG mepMappedAttr: 2019-01-17T11:03:11Z DEBUG cn: $cn 2019-01-17T11:03:11Z DEBUG memberHost: $dn 2019-01-17T11:03:11Z DEBUG description: ipaNetgroup $cn 2019-01-17T11:03:11Z DEBUG mepStaticAttr: 2019-01-17T11:03:11Z DEBUG ipaUniqueId: autogenerate 2019-01-17T11:03:11Z DEBUG objectclass: ipanisnetgroup 2019-01-17T11:03:11Z DEBUG objectclass: ipaobject 2019-01-17T11:03:11Z DEBUG nisDomainName: local 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG NGP HGP Template 2019-01-17T11:03:11Z DEBUG mepRDNAttr: 2019-01-17T11:03:11Z DEBUG cn 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=NGP Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=NGP Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG NGP Definition 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG managedbase: 2019-01-17T11:03:11Z DEBUG cn=ng,cn=alt,dc=local 2019-01-17T11:03:11Z DEBUG originfilter: 2019-01-17T11:03:11Z DEBUG objectclass=ipahostgroup 2019-01-17T11:03:11Z DEBUG originscope: 2019-01-17T11:03:11Z DEBUG cn=hostgroups,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG managedtemplate: 2019-01-17T11:03:11Z DEBUG cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG only: set cn to 'NGP Definition', current value [u'NGP Definition'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'NGP Definition'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=NGP Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG NGP Definition 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG managedbase: 2019-01-17T11:03:11Z DEBUG cn=ng,cn=alt,dc=local 2019-01-17T11:03:11Z DEBUG originfilter: 2019-01-17T11:03:11Z DEBUG objectclass=ipahostgroup 2019-01-17T11:03:11Z DEBUG originscope: 2019-01-17T11:03:11Z DEBUG cn=hostgroups,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG managedtemplate: 2019-01-17T11:03:11Z DEBUG cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Parsing update file '/usr/share/ipa/updates/20-idoverride_index.update' 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=ipaOriginalUid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=ipaOriginalUid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipaOriginalUid 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=ipaOriginalUid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipaOriginalUid 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipaAnchorUUID 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipaAnchorUUID 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipaAnchorUUID 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG remove: 'ipaOriginalUid' from cn, current value [u'ipaAnchorUUID'] 2019-01-17T11:03:11Z DEBUG remove: 'ipaOriginalUid' not in cn 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipaAnchorUUID 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Parsing update file '/usr/share/ipa/updates/20-indices.update' 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=memberuid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=memberuid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG memberuid 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=memberuid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG memberuid 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=memberHost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=memberHost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG memberHost 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=memberHost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG memberHost 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=memberUser,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=memberUser,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG memberUser 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=memberUser,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG memberUser 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=member,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=member,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG member 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=member,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG member 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=uniquemember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=uniquemember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG uniquemember 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'sub'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'sub', current value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'sub'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=uniquemember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG uniquemember 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=owner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=owner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG owner 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'sub'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'sub', current value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'sub'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=owner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG owner 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=manager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=manager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG manager 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=manager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG manager 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=secretary,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=secretary,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG secretary 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=secretary,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG secretary 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=seeAlso,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=seeAlso,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG seeAlso 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'sub'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'sub', current value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'sub'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=seeAlso,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG seeAlso 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=memberOf,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=memberOf,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG memberOf 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=memberOf,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG memberOf 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=fqdn,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=fqdn,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG fqdn 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=fqdn,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG fqdn 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=macAddress,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=macAddress,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG macAddress 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=macAddress,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG macAddress 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=sourcehost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=sourcehost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG sourcehost 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=sourcehost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG sourcehost 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=memberservice,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=memberservice,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG memberservice 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=memberservice,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG memberservice 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=managedby,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=managedby,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG managedby 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=managedby,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG managedby 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=memberallowcmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=memberallowcmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG memberallowcmd 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=memberallowcmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG memberallowcmd 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=memberdenycmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=memberdenycmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG memberdenycmd 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=memberdenycmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG memberdenycmd 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=ipasudorunas,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=ipasudorunas,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipasudorunas 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=ipasudorunas,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipasudorunas 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=ipasudorunasgroup,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=ipasudorunasgroup,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipasudorunasgroup 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=ipasudorunasgroup,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipasudorunasgroup 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=automountkey,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=automountkey,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG automountkey 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=automountkey,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG automountkey 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=ipakrbprincipalalias,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=ipakrbprincipalalias,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipakrbprincipalalias 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=ipakrbprincipalalias,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipakrbprincipalalias 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=ipauniqueid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=ipauniqueid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipauniqueid 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=ipauniqueid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipauniqueid 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=ipatokenradiusconfiglink,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=ipatokenradiusconfiglink,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipatokenradiusconfiglink 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=ipatokenradiusconfiglink,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipatokenradiusconfiglink 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=ipaassignedidview,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=ipaassignedidview,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipaassignedidview 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=ipaassignedidview,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipaassignedidview 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=ipaallowedtarget,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=ipaallowedtarget,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipaallowedtarget 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=ipaallowedtarget,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipaallowedtarget 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=ipaMemberCa,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=ipaMemberCa,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipaMemberCa 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=ipaMemberCa,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipaMemberCa 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=ipaMemberCertProfile,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=ipaMemberCertProfile,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipaMemberCertProfile 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres', u'sub'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'sub', current value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres', u'sub'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=ipaMemberCertProfile,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipaMemberCertProfile 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=userCertificate,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=userCertificate,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG userCertificate 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG only: set nsSystemIndex to 'false', current value [u'false'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'false'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=userCertificate,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG userCertificate 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ntUniqueId 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ntUniqueId 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ntUserDomainId 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ntUserDomainId 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=ipalocation,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=ipalocation,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipalocation 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=ipalocation,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipalocation 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=krbPrincipalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=krbPrincipalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG nsMatchingRule: 2019-01-17T11:03:11Z DEBUG caseIgnoreIA5Match 2019-01-17T11:03:11Z DEBUG caseExactIA5Match 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG krbPrincipalName 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG only: set nsMatchingRule to 'caseIgnoreIA5Match', current value [u'caseIgnoreIA5Match', u'caseExactIA5Match'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'caseIgnoreIA5Match'] 2019-01-17T11:03:11Z DEBUG only: set nsMatchingRule to 'caseExactIA5Match', current value [u'caseIgnoreIA5Match'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'caseIgnoreIA5Match', u'caseExactIA5Match'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'sub'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'sub', current value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'sub'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=krbPrincipalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG nsMatchingRule: 2019-01-17T11:03:11Z DEBUG caseIgnoreIA5Match 2019-01-17T11:03:11Z DEBUG caseExactIA5Match 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG krbPrincipalName 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=krbCanonicalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=krbCanonicalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG krbCanonicalName 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG only: set nsSystemIndex to 'false', current value [u'false'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'false'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'sub'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'sub', current value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'sub'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=krbCanonicalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG krbCanonicalName 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=serverhostname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=serverhostname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG serverhostname 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG only: set nsSystemIndex to 'false', current value [u'false'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'false'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'sub'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'sub', current value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'sub'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=serverhostname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG serverhostname 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=description,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=description,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsindex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG description 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=description,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsindex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG description 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=l,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=l,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsindex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG l 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=l,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsindex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG l 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=nsOsVersion,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=nsOsVersion,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsindex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG nsOsVersion 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=nsOsVersion,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsindex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG nsOsVersion 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=nsHardwarePlatform,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=nsHardwarePlatform,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsindex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG nsHardwarePlatform 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=nsHardwarePlatform,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsindex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG nsHardwarePlatform 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=nsHostLocation,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=nsHostLocation,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsindex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG nsHostLocation 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=nsHostLocation,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG sub 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsindex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG nsHostLocation 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Parsing update file '/usr/share/ipa/updates/20-ipaservers_hostgroup.update' 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=ipaservers,cn=hostgroups,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG groupOfNames 2019-01-17T11:03:11Z DEBUG nestedGroup 2019-01-17T11:03:11Z DEBUG ipaobject 2019-01-17T11:03:11Z DEBUG ipahostgroup 2019-01-17T11:03:11Z DEBUG member: 2019-01-17T11:03:11Z DEBUG fqdn=centos75.local,cn=computers,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipaservers 2019-01-17T11:03:11Z DEBUG ipaUniqueID: 2019-01-17T11:03:11Z DEBUG 975b5bc8-1a43-11e9-bd08-5254007fd04f 2019-01-17T11:03:11Z DEBUG description: 2019-01-17T11:03:11Z DEBUG IPA server hosts 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG groupOfNames 2019-01-17T11:03:11Z DEBUG nestedGroup 2019-01-17T11:03:11Z DEBUG ipaobject 2019-01-17T11:03:11Z DEBUG ipahostgroup 2019-01-17T11:03:11Z DEBUG member: 2019-01-17T11:03:11Z DEBUG fqdn=centos75.local,cn=computers,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipaservers 2019-01-17T11:03:11Z DEBUG ipaUniqueID: 2019-01-17T11:03:11Z DEBUG 975b5bc8-1a43-11e9-bd08-5254007fd04f 2019-01-17T11:03:11Z DEBUG description: 2019-01-17T11:03:11Z DEBUG IPA server hosts 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=ipaservers,cn=hostgroups,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG groupOfNames 2019-01-17T11:03:11Z DEBUG nestedGroup 2019-01-17T11:03:11Z DEBUG ipaobject 2019-01-17T11:03:11Z DEBUG ipahostgroup 2019-01-17T11:03:11Z DEBUG member: 2019-01-17T11:03:11Z DEBUG fqdn=centos75.local,cn=computers,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipaservers 2019-01-17T11:03:11Z DEBUG ipaUniqueID: 2019-01-17T11:03:11Z DEBUG 975b5bc8-1a43-11e9-bd08-5254007fd04f 2019-01-17T11:03:11Z DEBUG description: 2019-01-17T11:03:11Z DEBUG IPA server hosts 2019-01-17T11:03:11Z DEBUG add: 'fqdn=centos75.local,cn=computers,cn=accounts,dc=local' to member, current value [u'fqdn=centos75.local,cn=computers,cn=accounts,dc=local'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'fqdn=centos75.local,cn=computers,cn=accounts,dc=local'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG groupOfNames 2019-01-17T11:03:11Z DEBUG nestedGroup 2019-01-17T11:03:11Z DEBUG ipaobject 2019-01-17T11:03:11Z DEBUG ipahostgroup 2019-01-17T11:03:11Z DEBUG member: 2019-01-17T11:03:11Z DEBUG fqdn=centos75.local,cn=computers,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipaservers 2019-01-17T11:03:11Z DEBUG ipaUniqueID: 2019-01-17T11:03:11Z DEBUG 975b5bc8-1a43-11e9-bd08-5254007fd04f 2019-01-17T11:03:11Z DEBUG description: 2019-01-17T11:03:11Z DEBUG IPA server hosts 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Parsing update file '/usr/share/ipa/updates/20-nss_ldap.update' 2019-01-17T11:03:11Z DEBUG Updating existing entry: dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG domain 2019-01-17T11:03:11Z DEBUG pilotObject 2019-01-17T11:03:11Z DEBUG info: 2019-01-17T11:03:11Z DEBUG IPA V2.0 2019-01-17T11:03:11Z DEBUG aci: 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2019-01-17T11:03:11Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:11Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:11Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:11Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:11Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:11Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG dc: 2019-01-17T11:03:11Z DEBUG local 2019-01-17T11:03:11Z DEBUG add: 'domain' to objectClass, current value [u'top', u'domain', u'pilotObject'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'top', u'pilotObject', u'domain'] 2019-01-17T11:03:11Z DEBUG add: 'domainRelatedObject' to objectClass, current value [u'top', u'pilotObject', u'domain'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'top', u'pilotObject', u'domain', u'domainRelatedObject'] 2019-01-17T11:03:11Z DEBUG add: 'nisDomainObject' to objectClass, current value [u'top', u'pilotObject', u'domain', u'domainRelatedObject'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'top', u'pilotObject', u'domain', u'domainRelatedObject', u'nisDomainObject'] 2019-01-17T11:03:11Z DEBUG add: 'local' to associatedDomain, current value [] 2019-01-17T11:03:11Z DEBUG add: updated value [u'local'] 2019-01-17T11:03:11Z DEBUG add: 'local' to nisDomain, current value [] 2019-01-17T11:03:11Z DEBUG add: updated value [u'local'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: dc=local 2019-01-17T11:03:11Z DEBUG info: 2019-01-17T11:03:11Z DEBUG IPA V2.0 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG pilotObject 2019-01-17T11:03:11Z DEBUG domain 2019-01-17T11:03:11Z DEBUG domainRelatedObject 2019-01-17T11:03:11Z DEBUG nisDomainObject 2019-01-17T11:03:11Z DEBUG aci: 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2019-01-17T11:03:11Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:11Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:11Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:11Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:11Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:11Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG dc: 2019-01-17T11:03:11Z DEBUG local 2019-01-17T11:03:11Z DEBUG nisDomain: 2019-01-17T11:03:11Z DEBUG local 2019-01-17T11:03:11Z DEBUG associatedDomain: 2019-01-17T11:03:11Z DEBUG local 2019-01-17T11:03:11Z DEBUG [(0, u'objectClass', [u'domainRelatedObject', u'nisDomainObject']), (2, u'nisDomain', [u'local']), (2, u'associatedDomain', [u'local'])] 2019-01-17T11:03:11Z DEBUG Updated 1 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG New entry: ou=profile,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: ou=profile,dc=local 2019-01-17T11:03:11Z DEBUG add: 'top' to objectClass, current value [] 2019-01-17T11:03:11Z DEBUG add: updated value [u'top'] 2019-01-17T11:03:11Z DEBUG add: 'organizationalUnit' to objectClass, current value [u'top'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'top', u'organizationalUnit'] 2019-01-17T11:03:11Z DEBUG add: 'profiles' to ou, current value [] 2019-01-17T11:03:11Z DEBUG add: updated value [u'profiles'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: ou=profile,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG organizationalUnit 2019-01-17T11:03:11Z DEBUG ou: 2019-01-17T11:03:11Z DEBUG profiles 2019-01-17T11:03:11Z DEBUG New entry: cn=default,ou=profile,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=default,ou=profile,dc=local 2019-01-17T11:03:11Z DEBUG defaultServerList: 2019-01-17T11:03:11Z DEBUG centos75.local 2019-01-17T11:03:11Z DEBUG defaultSearchBase: 2019-01-17T11:03:11Z DEBUG dc=local 2019-01-17T11:03:11Z DEBUG ObjectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG DUAConfigProfile 2019-01-17T11:03:11Z DEBUG serviceSearchDescriptor: 2019-01-17T11:03:11Z DEBUG passwd:cn=users,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG group:cn=groups,cn=compat,dc=local 2019-01-17T11:03:11Z DEBUG searchTimeLimit: 2019-01-17T11:03:11Z DEBUG 15 2019-01-17T11:03:11Z DEBUG followReferrals: 2019-01-17T11:03:11Z DEBUG TRUE 2019-01-17T11:03:11Z DEBUG objectClassMap: 2019-01-17T11:03:11Z DEBUG shadow:shadowAccount=posixAccount 2019-01-17T11:03:11Z DEBUG bindTimeLimit: 2019-01-17T11:03:11Z DEBUG 5 2019-01-17T11:03:11Z DEBUG authenticationMethod: 2019-01-17T11:03:11Z DEBUG none 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG default 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=default,ou=profile,dc=local 2019-01-17T11:03:11Z DEBUG defaultServerList: 2019-01-17T11:03:11Z DEBUG centos75.local 2019-01-17T11:03:11Z DEBUG defaultSearchBase: 2019-01-17T11:03:11Z DEBUG dc=local 2019-01-17T11:03:11Z DEBUG ObjectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG DUAConfigProfile 2019-01-17T11:03:11Z DEBUG serviceSearchDescriptor: 2019-01-17T11:03:11Z DEBUG passwd:cn=users,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG group:cn=groups,cn=compat,dc=local 2019-01-17T11:03:11Z DEBUG searchTimeLimit: 2019-01-17T11:03:11Z DEBUG 15 2019-01-17T11:03:11Z DEBUG followReferrals: 2019-01-17T11:03:11Z DEBUG TRUE 2019-01-17T11:03:11Z DEBUG objectClassMap: 2019-01-17T11:03:11Z DEBUG shadow:shadowAccount=posixAccount 2019-01-17T11:03:11Z DEBUG bindTimeLimit: 2019-01-17T11:03:11Z DEBUG 5 2019-01-17T11:03:11Z DEBUG authenticationMethod: 2019-01-17T11:03:11Z DEBUG none 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG default 2019-01-17T11:03:11Z DEBUG Parsing update file '/usr/share/ipa/updates/20-replication.update' 2019-01-17T11:03:11Z DEBUG New entry: cn=replication,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=replication,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectclass: 2019-01-17T11:03:11Z DEBUG nsDS5Replica 2019-01-17T11:03:11Z DEBUG nsDS5ReplicaId: 2019-01-17T11:03:11Z DEBUG 3 2019-01-17T11:03:11Z DEBUG nsDS5ReplicaRoot: 2019-01-17T11:03:11Z DEBUG dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=replication,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectclass: 2019-01-17T11:03:11Z DEBUG nsDS5Replica 2019-01-17T11:03:11Z DEBUG nsDS5ReplicaId: 2019-01-17T11:03:11Z DEBUG 3 2019-01-17T11:03:11Z DEBUG nsDS5ReplicaRoot: 2019-01-17T11:03:11Z DEBUG dc=local 2019-01-17T11:03:11Z DEBUG New entry: cn=replication managers,cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=replication managers,cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectclass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG groupofnames 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG replication managers 2019-01-17T11:03:11Z DEBUG add: 'krbprincipalname=ldap/centos75.local@LOCAL,cn=services,cn=accounts,dc=local' to member, current value [] 2019-01-17T11:03:11Z DEBUG add: updated value [u'krbprincipalname=ldap/centos75.local@LOCAL,cn=services,cn=accounts,dc=local'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=replication managers,cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectclass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG groupofnames 2019-01-17T11:03:11Z DEBUG member: 2019-01-17T11:03:11Z DEBUG krbprincipalname=ldap/centos75.local@LOCAL,cn=services,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG replication managers 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG topology 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG topology 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=domain,cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=domain,cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG nsds5ReplicaStripAttrs: 2019-01-17T11:03:11Z DEBUG modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp 2019-01-17T11:03:11Z DEBUG ipaReplTopoConfRoot: 2019-01-17T11:03:11Z DEBUG dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG iparepltopoconf 2019-01-17T11:03:11Z DEBUG nsDS5ReplicatedAttributeListTotal: 2019-01-17T11:03:11Z DEBUG (objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount 2019-01-17T11:03:11Z DEBUG nsDS5ReplicatedAttributeList: 2019-01-17T11:03:11Z DEBUG (objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG domain 2019-01-17T11:03:11Z DEBUG add: '(objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount' to nsDS5ReplicatedAttributeList, current value [u'(objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'(objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount'] 2019-01-17T11:03:11Z DEBUG add: '(objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount' to nsDS5ReplicatedAttributeListTotal, current value [u'(objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'(objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount'] 2019-01-17T11:03:11Z DEBUG add: 'modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp' to nsds5ReplicaStripAttrs, current value [u'modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=domain,cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG nsds5ReplicaStripAttrs: 2019-01-17T11:03:11Z DEBUG modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp 2019-01-17T11:03:11Z DEBUG ipaReplTopoConfRoot: 2019-01-17T11:03:11Z DEBUG dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG iparepltopoconf 2019-01-17T11:03:11Z DEBUG nsDS5ReplicatedAttributeListTotal: 2019-01-17T11:03:11Z DEBUG (objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount 2019-01-17T11:03:11Z DEBUG nsDS5ReplicatedAttributeList: 2019-01-17T11:03:11Z DEBUG (objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG domain 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Deleting entry cn=realm,cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG cn=realm,cn=topology,cn=ipa,cn=etc,dc=local did not exist:no such entry 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=centos75.local,cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=centos75.local,cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG ipaReplTopoManagedServer 2019-01-17T11:03:11Z DEBUG ipaConfigObject 2019-01-17T11:03:11Z DEBUG ipaSupportedDomainLevelConfig 2019-01-17T11:03:11Z DEBUG ipaMaxDomainLevel: 2019-01-17T11:03:11Z DEBUG 1 2019-01-17T11:03:11Z DEBUG ipaMinDomainLevel: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG centos75.local 2019-01-17T11:03:11Z DEBUG ipaReplTopoManagedSuffix: 2019-01-17T11:03:11Z DEBUG dc=local 2019-01-17T11:03:11Z DEBUG add: 'ipaReplTopoManagedServer' to objectclass, current value [u'top', u'nsContainer', u'ipaReplTopoManagedServer', u'ipaConfigObject', u'ipaSupportedDomainLevelConfig'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'top', u'nsContainer', u'ipaConfigObject', u'ipaSupportedDomainLevelConfig', u'ipaReplTopoManagedServer'] 2019-01-17T11:03:11Z DEBUG add: 'dc=local' to ipaReplTopoManagedSuffix, current value [u'dc=local'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'dc=local'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=centos75.local,cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG ipaConfigObject 2019-01-17T11:03:11Z DEBUG ipaSupportedDomainLevelConfig 2019-01-17T11:03:11Z DEBUG ipaReplTopoManagedServer 2019-01-17T11:03:11Z DEBUG ipaMaxDomainLevel: 2019-01-17T11:03:11Z DEBUG 1 2019-01-17T11:03:11Z DEBUG ipaMinDomainLevel: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG centos75.local 2019-01-17T11:03:11Z DEBUG ipaReplTopoManagedSuffix: 2019-01-17T11:03:11Z DEBUG dc=local 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=IPA Topology Configuration,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=IPA Topology Configuration,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG ipa-topology-plugin 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG IPA Topology Configuration 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG ipa_topo_init 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-named: 2019-01-17T11:03:11Z DEBUG ldbm database 2019-01-17T11:03:11Z DEBUG Multimaster Replication Plugin 2019-01-17T11:03:11Z DEBUG nsslapd-topo-plugin-shared-replica-root: 2019-01-17T11:03:11Z DEBUG dc=local 2019-01-17T11:03:11Z DEBUG o=ipaca 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.0 2019-01-17T11:03:11Z DEBUG nsslapd-topo-plugin-shared-config-base: 2019-01-17T11:03:11Z DEBUG cn=ipa,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG ipa-topology-plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libtopology 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG object 2019-01-17T11:03:11Z DEBUG nsslapd-topo-plugin-shared-binddngroup: 2019-01-17T11:03:11Z DEBUG cn=replication managers,cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG nsslapd-topo-plugin-startup-delay: 2019-01-17T11:03:11Z DEBUG 20 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG freeipa 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=IPA Topology Configuration,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG ipa-topology-plugin 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG IPA Topology Configuration 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG ipa_topo_init 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-named: 2019-01-17T11:03:11Z DEBUG ldbm database 2019-01-17T11:03:11Z DEBUG Multimaster Replication Plugin 2019-01-17T11:03:11Z DEBUG nsslapd-topo-plugin-shared-replica-root: 2019-01-17T11:03:11Z DEBUG dc=local 2019-01-17T11:03:11Z DEBUG o=ipaca 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.0 2019-01-17T11:03:11Z DEBUG nsslapd-topo-plugin-shared-config-base: 2019-01-17T11:03:11Z DEBUG cn=ipa,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG ipa-topology-plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libtopology 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG object 2019-01-17T11:03:11Z DEBUG nsslapd-topo-plugin-shared-binddngroup: 2019-01-17T11:03:11Z DEBUG cn=replication managers,cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG nsslapd-topo-plugin-startup-delay: 2019-01-17T11:03:11Z DEBUG 20 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG freeipa 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG New entry: cn=changelog5,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=changelog5,cn=config 2019-01-17T11:03:11Z DEBUG addifnew: '7d' to nsslapd-changelogmaxage, current value [] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=changelog5,cn=config 2019-01-17T11:03:11Z DEBUG Parsing update file '/usr/share/ipa/updates/20-sslciphers.update' 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=encryption,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=encryption,cn=config 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG encryption 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsEncryptionConfig 2019-01-17T11:03:11Z DEBUG sslVersionMin: 2019-01-17T11:03:11Z DEBUG TLS1.0 2019-01-17T11:03:11Z DEBUG nsSSLSupportedCiphers: 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384::AES::SHA384::256 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_ECDSA_WITH_RC4_128_SHA::RC4::SHA1::128 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384::AES::SHA384::256 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2019-01-17T11:03:11Z DEBUG TLS_DHE_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2019-01-17T11:03:11Z DEBUG TLS_DHE_DSS_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2019-01-17T11:03:11Z DEBUG TLS_DHE_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2019-01-17T11:03:11Z DEBUG TLS_DHE_DSS_WITH_AES_256_CBC_SHA::AES::SHA1::256 2019-01-17T11:03:11Z DEBUG TLS_DHE_RSA_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2019-01-17T11:03:11Z DEBUG TLS_DHE_DSS_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2019-01-17T11:03:11Z DEBUG TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2019-01-17T11:03:11Z DEBUG TLS_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2019-01-17T11:03:11Z DEBUG TLS_DHE_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2019-01-17T11:03:11Z DEBUG TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2019-01-17T11:03:11Z DEBUG TLS_DHE_DSS_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2019-01-17T11:03:11Z DEBUG TLS_DHE_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2019-01-17T11:03:11Z DEBUG TLS_DHE_DSS_WITH_AES_128_CBC_SHA::AES::SHA1::128 2019-01-17T11:03:11Z DEBUG TLS_DHE_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2019-01-17T11:03:11Z DEBUG TLS_DHE_DSS_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2019-01-17T11:03:11Z DEBUG TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2019-01-17T11:03:11Z DEBUG TLS_DHE_DSS_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2019-01-17T11:03:11Z DEBUG TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2019-01-17T11:03:11Z DEBUG TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2019-01-17T11:03:11Z DEBUG TLS_DHE_DSS_WITH_RC4_128_SHA::RC4::SHA1::128 2019-01-17T11:03:11Z DEBUG TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2019-01-17T11:03:11Z DEBUG TLS_ECDH_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2019-01-17T11:03:11Z DEBUG TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2019-01-17T11:03:11Z DEBUG TLS_ECDH_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2019-01-17T11:03:11Z DEBUG TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2019-01-17T11:03:11Z DEBUG TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2019-01-17T11:03:11Z DEBUG TLS_ECDH_ECDSA_WITH_RC4_128_SHA::RC4::SHA1::128 2019-01-17T11:03:11Z DEBUG TLS_ECDH_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2019-01-17T11:03:11Z DEBUG TLS_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2019-01-17T11:03:11Z DEBUG TLS_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2019-01-17T11:03:11Z DEBUG TLS_RSA_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2019-01-17T11:03:11Z DEBUG TLS_RSA_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2019-01-17T11:03:11Z DEBUG TLS_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2019-01-17T11:03:11Z DEBUG TLS_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2019-01-17T11:03:11Z DEBUG TLS_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2019-01-17T11:03:11Z DEBUG TLS_RSA_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2019-01-17T11:03:11Z DEBUG TLS_RSA_WITH_SEED_CBC_SHA::SEED::SHA1::128 2019-01-17T11:03:11Z DEBUG TLS_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2019-01-17T11:03:11Z DEBUG TLS_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2019-01-17T11:03:11Z DEBUG TLS_RSA_WITH_RC4_128_MD5::RC4::MD5::128 2019-01-17T11:03:11Z DEBUG TLS_DHE_RSA_WITH_DES_CBC_SHA::DES::SHA1::64 2019-01-17T11:03:11Z DEBUG TLS_DHE_DSS_WITH_DES_CBC_SHA::DES::SHA1::64 2019-01-17T11:03:11Z DEBUG TLS_RSA_WITH_DES_CBC_SHA::DES::SHA1::64 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_ECDSA_WITH_NULL_SHA::NULL::SHA1::0 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_RSA_WITH_NULL_SHA::NULL::SHA1::0 2019-01-17T11:03:11Z DEBUG TLS_ECDH_RSA_WITH_NULL_SHA::NULL::SHA1::0 2019-01-17T11:03:11Z DEBUG TLS_ECDH_ECDSA_WITH_NULL_SHA::NULL::SHA1::0 2019-01-17T11:03:11Z DEBUG TLS_RSA_WITH_NULL_SHA::NULL::SHA1::0 2019-01-17T11:03:11Z DEBUG TLS_RSA_WITH_NULL_SHA256::NULL::SHA256::0 2019-01-17T11:03:11Z DEBUG TLS_RSA_WITH_NULL_MD5::NULL::MD5::0 2019-01-17T11:03:11Z DEBUG TLS_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2019-01-17T11:03:11Z DEBUG TLS_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2019-01-17T11:03:11Z DEBUG TLS_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2019-01-17T11:03:11Z DEBUG nsSSLClientAuth: 2019-01-17T11:03:11Z DEBUG allowed 2019-01-17T11:03:11Z DEBUG nsSSLSessionTimeout: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG allowWeakCipher: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG CACertExtractFile: 2019-01-17T11:03:11Z DEBUG /etc/dirsrv/slapd-LOCAL/LOCAL20IPA20CA.pem 2019-01-17T11:03:11Z DEBUG nsSSL3Ciphers: 2019-01-17T11:03:11Z DEBUG default 2019-01-17T11:03:11Z DEBUG only: set nsSSL3Ciphers to 'default', current value [u'default'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'default'] 2019-01-17T11:03:11Z DEBUG addifnew: 'off' to allowWeakCipher, current value [u'off'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=encryption,cn=config 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG encryption 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsEncryptionConfig 2019-01-17T11:03:11Z DEBUG sslVersionMin: 2019-01-17T11:03:11Z DEBUG TLS1.0 2019-01-17T11:03:11Z DEBUG nsSSLSupportedCiphers: 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384::AES::SHA384::256 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_ECDSA_WITH_RC4_128_SHA::RC4::SHA1::128 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384::AES::SHA384::256 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2019-01-17T11:03:11Z DEBUG TLS_DHE_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2019-01-17T11:03:11Z DEBUG TLS_DHE_DSS_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2019-01-17T11:03:11Z DEBUG TLS_DHE_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2019-01-17T11:03:11Z DEBUG TLS_DHE_DSS_WITH_AES_256_CBC_SHA::AES::SHA1::256 2019-01-17T11:03:11Z DEBUG TLS_DHE_RSA_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2019-01-17T11:03:11Z DEBUG TLS_DHE_DSS_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2019-01-17T11:03:11Z DEBUG TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2019-01-17T11:03:11Z DEBUG TLS_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2019-01-17T11:03:11Z DEBUG TLS_DHE_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2019-01-17T11:03:11Z DEBUG TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2019-01-17T11:03:11Z DEBUG TLS_DHE_DSS_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2019-01-17T11:03:11Z DEBUG TLS_DHE_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2019-01-17T11:03:11Z DEBUG TLS_DHE_DSS_WITH_AES_128_CBC_SHA::AES::SHA1::128 2019-01-17T11:03:11Z DEBUG TLS_DHE_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2019-01-17T11:03:11Z DEBUG TLS_DHE_DSS_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2019-01-17T11:03:11Z DEBUG TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2019-01-17T11:03:11Z DEBUG TLS_DHE_DSS_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2019-01-17T11:03:11Z DEBUG TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2019-01-17T11:03:11Z DEBUG TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2019-01-17T11:03:11Z DEBUG TLS_DHE_DSS_WITH_RC4_128_SHA::RC4::SHA1::128 2019-01-17T11:03:11Z DEBUG TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2019-01-17T11:03:11Z DEBUG TLS_ECDH_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2019-01-17T11:03:11Z DEBUG TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2019-01-17T11:03:11Z DEBUG TLS_ECDH_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2019-01-17T11:03:11Z DEBUG TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2019-01-17T11:03:11Z DEBUG TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2019-01-17T11:03:11Z DEBUG TLS_ECDH_ECDSA_WITH_RC4_128_SHA::RC4::SHA1::128 2019-01-17T11:03:11Z DEBUG TLS_ECDH_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2019-01-17T11:03:11Z DEBUG TLS_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2019-01-17T11:03:11Z DEBUG TLS_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2019-01-17T11:03:11Z DEBUG TLS_RSA_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2019-01-17T11:03:11Z DEBUG TLS_RSA_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2019-01-17T11:03:11Z DEBUG TLS_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2019-01-17T11:03:11Z DEBUG TLS_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2019-01-17T11:03:11Z DEBUG TLS_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2019-01-17T11:03:11Z DEBUG TLS_RSA_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2019-01-17T11:03:11Z DEBUG TLS_RSA_WITH_SEED_CBC_SHA::SEED::SHA1::128 2019-01-17T11:03:11Z DEBUG TLS_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2019-01-17T11:03:11Z DEBUG TLS_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2019-01-17T11:03:11Z DEBUG TLS_RSA_WITH_RC4_128_MD5::RC4::MD5::128 2019-01-17T11:03:11Z DEBUG TLS_DHE_RSA_WITH_DES_CBC_SHA::DES::SHA1::64 2019-01-17T11:03:11Z DEBUG TLS_DHE_DSS_WITH_DES_CBC_SHA::DES::SHA1::64 2019-01-17T11:03:11Z DEBUG TLS_RSA_WITH_DES_CBC_SHA::DES::SHA1::64 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_ECDSA_WITH_NULL_SHA::NULL::SHA1::0 2019-01-17T11:03:11Z DEBUG TLS_ECDHE_RSA_WITH_NULL_SHA::NULL::SHA1::0 2019-01-17T11:03:11Z DEBUG TLS_ECDH_RSA_WITH_NULL_SHA::NULL::SHA1::0 2019-01-17T11:03:11Z DEBUG TLS_ECDH_ECDSA_WITH_NULL_SHA::NULL::SHA1::0 2019-01-17T11:03:11Z DEBUG TLS_RSA_WITH_NULL_SHA::NULL::SHA1::0 2019-01-17T11:03:11Z DEBUG TLS_RSA_WITH_NULL_SHA256::NULL::SHA256::0 2019-01-17T11:03:11Z DEBUG TLS_RSA_WITH_NULL_MD5::NULL::MD5::0 2019-01-17T11:03:11Z DEBUG TLS_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2019-01-17T11:03:11Z DEBUG TLS_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2019-01-17T11:03:11Z DEBUG TLS_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2019-01-17T11:03:11Z DEBUG nsSSLClientAuth: 2019-01-17T11:03:11Z DEBUG allowed 2019-01-17T11:03:11Z DEBUG nsSSLSessionTimeout: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG allowWeakCipher: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG CACertExtractFile: 2019-01-17T11:03:11Z DEBUG /etc/dirsrv/slapd-LOCAL/LOCAL20IPA20CA.pem 2019-01-17T11:03:11Z DEBUG nsSSL3Ciphers: 2019-01-17T11:03:11Z DEBUG default 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Parsing update file '/usr/share/ipa/updates/20-syncrepl.update' 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=Retro Changelog Plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=Retro Changelog Plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-attribute: 2019-01-17T11:03:11Z DEBUG nsuniqueid:targetUniqueId 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Retro Changelog Plugin 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-named: 2019-01-17T11:03:11Z DEBUG Class of Service 2019-01-17T11:03:11Z DEBUG nsslapd-changelogmaxage: 2019-01-17T11:03:11Z DEBUG 2d 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG Retrocl Plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libretrocl-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-include-suffix: 2019-01-17T11:03:11Z DEBUG cn=dns,dc=local 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG retrocl 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG retrocl_plugin_init 2019-01-17T11:03:11Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:03:11Z DEBUG 25 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG object 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG only: set nsslapd-pluginEnabled to 'on', current value [u'on'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'on'] 2019-01-17T11:03:11Z DEBUG add: 'nsuniqueid:targetUniqueId' to nsslapd-attribute, current value [u'nsuniqueid:targetUniqueId'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'nsuniqueid:targetUniqueId'] 2019-01-17T11:03:11Z DEBUG add: '2d' to nsslapd-changelogmaxage, current value [u'2d'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'2d'] 2019-01-17T11:03:11Z DEBUG add: 'cn=dns,dc=local' to nsslapd-include-suffix, current value [u'cn=dns,dc=local'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'cn=dns,dc=local'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=Retro Changelog Plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-attribute: 2019-01-17T11:03:11Z DEBUG nsuniqueid:targetUniqueId 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Retro Changelog Plugin 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-named: 2019-01-17T11:03:11Z DEBUG Class of Service 2019-01-17T11:03:11Z DEBUG nsslapd-changelogmaxage: 2019-01-17T11:03:11Z DEBUG 2d 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG Retrocl Plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libretrocl-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-include-suffix: 2019-01-17T11:03:11Z DEBUG cn=dns,dc=local 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG retrocl 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG retrocl_plugin_init 2019-01-17T11:03:11Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:03:11Z DEBUG 25 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG object 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=MemberOf Plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=MemberOf Plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG memberof 2019-01-17T11:03:11Z DEBUG memberofgroupattr: 2019-01-17T11:03:11Z DEBUG member 2019-01-17T11:03:11Z DEBUG memberUser 2019-01-17T11:03:11Z DEBUG memberHost 2019-01-17T11:03:11Z DEBUG memberofentryscope: 2019-01-17T11:03:11Z DEBUG dc=local 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG MemberOf Plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG memberof plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libmemberof-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG memberofattr: 2019-01-17T11:03:11Z DEBUG memberOf 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG betxnpostoperation 2019-01-17T11:03:11Z DEBUG memberofentryscopeexcludesubtree: 2019-01-17T11:03:11Z DEBUG cn=compat,dc=local 2019-01-17T11:03:11Z DEBUG cn=provisioning,dc=local 2019-01-17T11:03:11Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG memberof_postop_init 2019-01-17T11:03:11Z DEBUG add: 'dc=local' to memberofentryscope, current value [u'dc=local'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'dc=local'] 2019-01-17T11:03:11Z DEBUG add: 'cn=compat,dc=local' to memberofentryscopeexcludesubtree, current value [u'cn=compat,dc=local', u'cn=provisioning,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'cn=provisioning,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local', u'cn=compat,dc=local'] 2019-01-17T11:03:11Z DEBUG add: 'cn=provisioning,dc=local' to memberofentryscopeexcludesubtree, current value [u'cn=provisioning,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local', u'cn=compat,dc=local'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'cn=topology,cn=ipa,cn=etc,dc=local', u'cn=compat,dc=local', u'cn=provisioning,dc=local'] 2019-01-17T11:03:11Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=local' to memberofentryscopeexcludesubtree, current value [u'cn=topology,cn=ipa,cn=etc,dc=local', u'cn=compat,dc=local', u'cn=provisioning,dc=local'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'cn=compat,dc=local', u'cn=provisioning,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=MemberOf Plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG memberof 2019-01-17T11:03:11Z DEBUG memberofgroupattr: 2019-01-17T11:03:11Z DEBUG member 2019-01-17T11:03:11Z DEBUG memberUser 2019-01-17T11:03:11Z DEBUG memberHost 2019-01-17T11:03:11Z DEBUG memberofentryscope: 2019-01-17T11:03:11Z DEBUG dc=local 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG MemberOf Plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG memberof plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libmemberof-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG memberofattr: 2019-01-17T11:03:11Z DEBUG memberOf 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG betxnpostoperation 2019-01-17T11:03:11Z DEBUG memberofentryscopeexcludesubtree: 2019-01-17T11:03:11Z DEBUG cn=compat,dc=local 2019-01-17T11:03:11Z DEBUG cn=provisioning,dc=local 2019-01-17T11:03:11Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG memberof_postop_init 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=referential integrity postoperation,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG referint 2019-01-17T11:03:11Z DEBUG nsslapd-plugincontainerscope: 2019-01-17T11:03:11Z DEBUG dc=local 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG referential integrity postoperation 2019-01-17T11:03:11Z DEBUG referint-update-delay: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-pluginexcludeentryscope: 2019-01-17T11:03:11Z DEBUG cn=provisioning,dc=local 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG referential integrity plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginentryscope: 2019-01-17T11:03:11Z DEBUG dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libreferint-plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:03:11Z DEBUG 40 2019-01-17T11:03:11Z DEBUG referint-logfile: 2019-01-17T11:03:11Z DEBUG /var/log/dirsrv/slapd-LOCAL/referint 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG betxnpostoperation 2019-01-17T11:03:11Z DEBUG referint-membership-attr: 2019-01-17T11:03:11Z DEBUG member 2019-01-17T11:03:11Z DEBUG uniquemember 2019-01-17T11:03:11Z DEBUG owner 2019-01-17T11:03:11Z DEBUG seeAlso 2019-01-17T11:03:11Z DEBUG manager 2019-01-17T11:03:11Z DEBUG secretary 2019-01-17T11:03:11Z DEBUG memberuser 2019-01-17T11:03:11Z DEBUG memberhost 2019-01-17T11:03:11Z DEBUG sourcehost 2019-01-17T11:03:11Z DEBUG memberservice 2019-01-17T11:03:11Z DEBUG managedby 2019-01-17T11:03:11Z DEBUG memberallowcmd 2019-01-17T11:03:11Z DEBUG memberdenycmd 2019-01-17T11:03:11Z DEBUG ipasudorunas 2019-01-17T11:03:11Z DEBUG ipasudorunasgroup 2019-01-17T11:03:11Z DEBUG ipatokenradiusconfiglink 2019-01-17T11:03:11Z DEBUG ipaassignedidview 2019-01-17T11:03:11Z DEBUG ipaallowedtarget 2019-01-17T11:03:11Z DEBUG ipamemberca 2019-01-17T11:03:11Z DEBUG ipamembercertprofile 2019-01-17T11:03:11Z DEBUG ipalocation 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG referint_postop_init 2019-01-17T11:03:11Z DEBUG add: 'dc=local' to nsslapd-plugincontainerscope, current value [u'dc=local'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'dc=local'] 2019-01-17T11:03:11Z DEBUG add: 'dc=local' to nsslapd-pluginentryscope, current value [u'dc=local'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'dc=local'] 2019-01-17T11:03:11Z DEBUG add: 'cn=provisioning,dc=local' to nsslapd-pluginExcludeEntryScope, current value [u'cn=provisioning,dc=local'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'cn=provisioning,dc=local'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG referint 2019-01-17T11:03:11Z DEBUG nsslapd-plugincontainerscope: 2019-01-17T11:03:11Z DEBUG dc=local 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG referential integrity postoperation 2019-01-17T11:03:11Z DEBUG referint-update-delay: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-pluginexcludeentryscope: 2019-01-17T11:03:11Z DEBUG cn=provisioning,dc=local 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG referential integrity plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginentryscope: 2019-01-17T11:03:11Z DEBUG dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libreferint-plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:03:11Z DEBUG 40 2019-01-17T11:03:11Z DEBUG referint-logfile: 2019-01-17T11:03:11Z DEBUG /var/log/dirsrv/slapd-LOCAL/referint 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG betxnpostoperation 2019-01-17T11:03:11Z DEBUG referint-membership-attr: 2019-01-17T11:03:11Z DEBUG member 2019-01-17T11:03:11Z DEBUG uniquemember 2019-01-17T11:03:11Z DEBUG owner 2019-01-17T11:03:11Z DEBUG seeAlso 2019-01-17T11:03:11Z DEBUG manager 2019-01-17T11:03:11Z DEBUG secretary 2019-01-17T11:03:11Z DEBUG memberuser 2019-01-17T11:03:11Z DEBUG memberhost 2019-01-17T11:03:11Z DEBUG sourcehost 2019-01-17T11:03:11Z DEBUG memberservice 2019-01-17T11:03:11Z DEBUG managedby 2019-01-17T11:03:11Z DEBUG memberallowcmd 2019-01-17T11:03:11Z DEBUG memberdenycmd 2019-01-17T11:03:11Z DEBUG ipasudorunas 2019-01-17T11:03:11Z DEBUG ipasudorunasgroup 2019-01-17T11:03:11Z DEBUG ipatokenradiusconfiglink 2019-01-17T11:03:11Z DEBUG ipaassignedidview 2019-01-17T11:03:11Z DEBUG ipaallowedtarget 2019-01-17T11:03:11Z DEBUG ipamemberca 2019-01-17T11:03:11Z DEBUG ipamembercertprofile 2019-01-17T11:03:11Z DEBUG ipalocation 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG referint_postop_init 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=Content Synchronization,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=Content Synchronization,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Content Synchronization 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-named: 2019-01-17T11:03:11Z DEBUG Retro Changelog Plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG Context Synchronization (RFC4533) plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libcontentsync-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG content-sync-plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG sync_init 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG object 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG only: set nsslapd-pluginEnabled to 'on', current value [u'on'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'on'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=Content Synchronization,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Content Synchronization 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-named: 2019-01-17T11:03:11Z DEBUG Retro Changelog Plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG Context Synchronization (RFC4533) plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libcontentsync-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG content-sync-plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG sync_init 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG object 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=IPA Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=IPA Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG IPA Unique IDs 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG ipauuidmagicregen: 2019-01-17T11:03:11Z DEBUG autogenerate 2019-01-17T11:03:11Z DEBUG ipauuidfilter: 2019-01-17T11:03:11Z DEBUG (|(objectclass=ipaObject)(objectclass=ipaAssociation)) 2019-01-17T11:03:11Z DEBUG ipauuidenforce: 2019-01-17T11:03:11Z DEBUG TRUE 2019-01-17T11:03:11Z DEBUG ipauuidexcludesubtree: 2019-01-17T11:03:11Z DEBUG cn=provisioning,dc=local 2019-01-17T11:03:11Z DEBUG ipauuidattr: 2019-01-17T11:03:11Z DEBUG ipaUniqueID 2019-01-17T11:03:11Z DEBUG ipauuidscope: 2019-01-17T11:03:11Z DEBUG dc=local 2019-01-17T11:03:11Z DEBUG add: 'cn=provisioning,dc=local' to ipaUuidExcludeSubtree, current value [u'cn=provisioning,dc=local'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'cn=provisioning,dc=local'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=IPA Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG IPA Unique IDs 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG ipauuidmagicregen: 2019-01-17T11:03:11Z DEBUG autogenerate 2019-01-17T11:03:11Z DEBUG ipauuidfilter: 2019-01-17T11:03:11Z DEBUG (|(objectclass=ipaObject)(objectclass=ipaAssociation)) 2019-01-17T11:03:11Z DEBUG ipauuidenforce: 2019-01-17T11:03:11Z DEBUG TRUE 2019-01-17T11:03:11Z DEBUG ipauuidexcludesubtree: 2019-01-17T11:03:11Z DEBUG cn=provisioning,dc=local 2019-01-17T11:03:11Z DEBUG ipauuidattr: 2019-01-17T11:03:11Z DEBUG ipaUniqueID 2019-01-17T11:03:11Z DEBUG ipauuidscope: 2019-01-17T11:03:11Z DEBUG dc=local 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Parsing update file '/usr/share/ipa/updates/20-user_private_groups.update' 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG mepTemplateEntry 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG mepMappedAttr: 2019-01-17T11:03:11Z DEBUG cn: $uid 2019-01-17T11:03:11Z DEBUG gidNumber: $uidNumber 2019-01-17T11:03:11Z DEBUG description: User private group for $uid 2019-01-17T11:03:11Z DEBUG mepStaticAttr: 2019-01-17T11:03:11Z DEBUG objectclass: posixgroup 2019-01-17T11:03:11Z DEBUG objectclass: ipaobject 2019-01-17T11:03:11Z DEBUG ipaUniqueId: autogenerate 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG UPG Template 2019-01-17T11:03:11Z DEBUG mepRDNAttr: 2019-01-17T11:03:11Z DEBUG cn 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG mepTemplateEntry 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG mepMappedAttr: 2019-01-17T11:03:11Z DEBUG cn: $uid 2019-01-17T11:03:11Z DEBUG gidNumber: $uidNumber 2019-01-17T11:03:11Z DEBUG description: User private group for $uid 2019-01-17T11:03:11Z DEBUG mepStaticAttr: 2019-01-17T11:03:11Z DEBUG objectclass: posixgroup 2019-01-17T11:03:11Z DEBUG objectclass: ipaobject 2019-01-17T11:03:11Z DEBUG ipaUniqueId: autogenerate 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG UPG Template 2019-01-17T11:03:11Z DEBUG mepRDNAttr: 2019-01-17T11:03:11Z DEBUG cn 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG UPG Definition 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG managedbase: 2019-01-17T11:03:11Z DEBUG cn=groups,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG originfilter: 2019-01-17T11:03:11Z DEBUG (&(objectclass=posixAccount)(!(description=__no_upg__))) 2019-01-17T11:03:11Z DEBUG originscope: 2019-01-17T11:03:11Z DEBUG cn=users,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG managedtemplate: 2019-01-17T11:03:11Z DEBUG cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG UPG Definition 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG managedbase: 2019-01-17T11:03:11Z DEBUG cn=groups,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG originfilter: 2019-01-17T11:03:11Z DEBUG (&(objectclass=posixAccount)(!(description=__no_upg__))) 2019-01-17T11:03:11Z DEBUG originscope: 2019-01-17T11:03:11Z DEBUG cn=users,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG managedtemplate: 2019-01-17T11:03:11Z DEBUG cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG UPG Definition 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG managedbase: 2019-01-17T11:03:11Z DEBUG cn=groups,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG originfilter: 2019-01-17T11:03:11Z DEBUG (&(objectclass=posixAccount)(!(description=__no_upg__))) 2019-01-17T11:03:11Z DEBUG originscope: 2019-01-17T11:03:11Z DEBUG cn=users,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG managedtemplate: 2019-01-17T11:03:11Z DEBUG cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG replace: objectclass=posixAccount not found, skipping 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG UPG Definition 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG managedbase: 2019-01-17T11:03:11Z DEBUG cn=groups,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG originfilter: 2019-01-17T11:03:11Z DEBUG (&(objectclass=posixAccount)(!(description=__no_upg__))) 2019-01-17T11:03:11Z DEBUG originscope: 2019-01-17T11:03:11Z DEBUG cn=users,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG managedtemplate: 2019-01-17T11:03:11Z DEBUG cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Parsing update file '/usr/share/ipa/updates/20-uuid.update' 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=IPK11 Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=IPK11 Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG IPK11 Unique IDs 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG ipauuidmagicregen: 2019-01-17T11:03:11Z DEBUG autogenerate 2019-01-17T11:03:11Z DEBUG ipauuidfilter: 2019-01-17T11:03:11Z DEBUG (objectclass=ipk11Object) 2019-01-17T11:03:11Z DEBUG ipauuidenforce: 2019-01-17T11:03:11Z DEBUG FALSE 2019-01-17T11:03:11Z DEBUG ipauuidscope: 2019-01-17T11:03:11Z DEBUG dc=local 2019-01-17T11:03:11Z DEBUG ipauuidattr: 2019-01-17T11:03:11Z DEBUG ipk11UniqueID 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=IPK11 Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG IPK11 Unique IDs 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG ipauuidmagicregen: 2019-01-17T11:03:11Z DEBUG autogenerate 2019-01-17T11:03:11Z DEBUG ipauuidfilter: 2019-01-17T11:03:11Z DEBUG (objectclass=ipk11Object) 2019-01-17T11:03:11Z DEBUG ipauuidenforce: 2019-01-17T11:03:11Z DEBUG FALSE 2019-01-17T11:03:11Z DEBUG ipauuidscope: 2019-01-17T11:03:11Z DEBUG dc=local 2019-01-17T11:03:11Z DEBUG ipauuidattr: 2019-01-17T11:03:11Z DEBUG ipk11UniqueID 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Parsing update file '/usr/share/ipa/updates/20-whoami.update' 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=whoami,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=whoami,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG whoami-plugin 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG whoami 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG whoami extended operation plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libwhoami-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG extendedop 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG whoami_init 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=whoami,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG whoami-plugin 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG whoami 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG whoami extended operation plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libwhoami-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG extendedop 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG whoami_init 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Parsing update file '/usr/share/ipa/updates/20-winsync_index.update' 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ntUniqueId 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ntUniqueId 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ntUserDomainId 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'eq', current value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: set nsIndexType to 'pres', current value [u'eq'] 2019-01-17T11:03:11Z DEBUG only: updated value [u'eq', u'pres'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsIndexType: 2019-01-17T11:03:11Z DEBUG eq 2019-01-17T11:03:11Z DEBUG pres 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsIndex 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ntUserDomainId 2019-01-17T11:03:11Z DEBUG nsSystemIndex: 2019-01-17T11:03:11Z DEBUG false 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Parsing update file '/usr/share/ipa/updates/21-ca_renewal_container.update' 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=ca_renewal,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=ca_renewal,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ca_renewal 2019-01-17T11:03:11Z DEBUG add: 'top' to objectClass, current value [u'nsContainer', u'top'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'nsContainer', u'top'] 2019-01-17T11:03:11Z DEBUG add: 'nsContainer' to objectClass, current value [u'nsContainer', u'top'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'top', u'nsContainer'] 2019-01-17T11:03:11Z DEBUG add: 'ca_renewal' to cn, current value [u'ca_renewal'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'ca_renewal'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=ca_renewal,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ca_renewal 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Parsing update file '/usr/share/ipa/updates/21-certstore_container.update' 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=certificates,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=certificates,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG certificates 2019-01-17T11:03:11Z DEBUG add: 'top' to objectClass, current value [u'nsContainer', u'top'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'nsContainer', u'top'] 2019-01-17T11:03:11Z DEBUG add: 'nsContainer' to objectClass, current value [u'nsContainer', u'top'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'top', u'nsContainer'] 2019-01-17T11:03:11Z DEBUG add: 'certificates' to cn, current value [u'certificates'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'certificates'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=certificates,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG certificates 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Parsing update file '/usr/share/ipa/updates/21-replicas_container.update' 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=replicas,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=replicas,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG replicas 2019-01-17T11:03:11Z DEBUG add: 'top' to objectClass, current value [u'nsContainer', u'top'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'nsContainer', u'top'] 2019-01-17T11:03:11Z DEBUG add: 'nsContainer' to objectClass, current value [u'nsContainer', u'top'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'top', u'nsContainer'] 2019-01-17T11:03:11Z DEBUG add: 'replicas' to cn, current value [u'replicas'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'replicas'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=replicas,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG replicas 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Parsing update file '/usr/share/ipa/updates/25-referint.update' 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=referential integrity postoperation,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG referint 2019-01-17T11:03:11Z DEBUG nsslapd-plugincontainerscope: 2019-01-17T11:03:11Z DEBUG dc=local 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG referential integrity postoperation 2019-01-17T11:03:11Z DEBUG referint-update-delay: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-pluginexcludeentryscope: 2019-01-17T11:03:11Z DEBUG cn=provisioning,dc=local 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG referential integrity plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginentryscope: 2019-01-17T11:03:11Z DEBUG dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libreferint-plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:03:11Z DEBUG 40 2019-01-17T11:03:11Z DEBUG referint-logfile: 2019-01-17T11:03:11Z DEBUG /var/log/dirsrv/slapd-LOCAL/referint 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG betxnpostoperation 2019-01-17T11:03:11Z DEBUG referint-membership-attr: 2019-01-17T11:03:11Z DEBUG member 2019-01-17T11:03:11Z DEBUG uniquemember 2019-01-17T11:03:11Z DEBUG owner 2019-01-17T11:03:11Z DEBUG seeAlso 2019-01-17T11:03:11Z DEBUG manager 2019-01-17T11:03:11Z DEBUG secretary 2019-01-17T11:03:11Z DEBUG memberuser 2019-01-17T11:03:11Z DEBUG memberhost 2019-01-17T11:03:11Z DEBUG sourcehost 2019-01-17T11:03:11Z DEBUG memberservice 2019-01-17T11:03:11Z DEBUG managedby 2019-01-17T11:03:11Z DEBUG memberallowcmd 2019-01-17T11:03:11Z DEBUG memberdenycmd 2019-01-17T11:03:11Z DEBUG ipasudorunas 2019-01-17T11:03:11Z DEBUG ipasudorunasgroup 2019-01-17T11:03:11Z DEBUG ipatokenradiusconfiglink 2019-01-17T11:03:11Z DEBUG ipaassignedidview 2019-01-17T11:03:11Z DEBUG ipaallowedtarget 2019-01-17T11:03:11Z DEBUG ipamemberca 2019-01-17T11:03:11Z DEBUG ipamembercertprofile 2019-01-17T11:03:11Z DEBUG ipalocation 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG referint_postop_init 2019-01-17T11:03:11Z DEBUG add: 'manager' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager'] 2019-01-17T11:03:11Z DEBUG add: 'secretary' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary'] 2019-01-17T11:03:11Z DEBUG add: 'memberuser' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser'] 2019-01-17T11:03:11Z DEBUG add: 'memberhost' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost'] 2019-01-17T11:03:11Z DEBUG add: 'sourcehost' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost'] 2019-01-17T11:03:11Z DEBUG add: 'memberservice' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice'] 2019-01-17T11:03:11Z DEBUG add: 'managedby' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby'] 2019-01-17T11:03:11Z DEBUG add: 'memberallowcmd' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd'] 2019-01-17T11:03:11Z DEBUG add: 'memberdenycmd' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd'] 2019-01-17T11:03:11Z DEBUG add: 'ipasudorunas' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas'] 2019-01-17T11:03:11Z DEBUG add: 'ipasudorunasgroup' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup'] 2019-01-17T11:03:11Z DEBUG add: 'ipatokenradiusconfiglink' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink'] 2019-01-17T11:03:11Z DEBUG add: 'ipaassignedidview' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview'] 2019-01-17T11:03:11Z DEBUG add: 'ipaallowedtarget' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget'] 2019-01-17T11:03:11Z DEBUG add: 'ipamemberca' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'ipamemberca', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca'] 2019-01-17T11:03:11Z DEBUG add: 'ipamembercertprofile' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'ipamembercertprofile', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile'] 2019-01-17T11:03:11Z DEBUG add: 'ipalocation' to referint-membership-attr, current value [u'member', u'uniquemember', u'owner', u'seeAlso', u'ipalocation', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'member', u'uniquemember', u'owner', u'seeAlso', u'manager', u'secretary', u'memberuser', u'memberhost', u'sourcehost', u'memberservice', u'managedby', u'memberallowcmd', u'memberdenycmd', u'ipasudorunas', u'ipasudorunasgroup', u'ipatokenradiusconfiglink', u'ipaassignedidview', u'ipaallowedtarget', u'ipamemberca', u'ipamembercertprofile', u'ipalocation'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG referint 2019-01-17T11:03:11Z DEBUG nsslapd-plugincontainerscope: 2019-01-17T11:03:11Z DEBUG dc=local 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG referential integrity postoperation 2019-01-17T11:03:11Z DEBUG referint-update-delay: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-pluginexcludeentryscope: 2019-01-17T11:03:11Z DEBUG cn=provisioning,dc=local 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG referential integrity plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginentryscope: 2019-01-17T11:03:11Z DEBUG dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libreferint-plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:03:11Z DEBUG 40 2019-01-17T11:03:11Z DEBUG referint-logfile: 2019-01-17T11:03:11Z DEBUG /var/log/dirsrv/slapd-LOCAL/referint 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG betxnpostoperation 2019-01-17T11:03:11Z DEBUG referint-membership-attr: 2019-01-17T11:03:11Z DEBUG member 2019-01-17T11:03:11Z DEBUG uniquemember 2019-01-17T11:03:11Z DEBUG owner 2019-01-17T11:03:11Z DEBUG seeAlso 2019-01-17T11:03:11Z DEBUG manager 2019-01-17T11:03:11Z DEBUG secretary 2019-01-17T11:03:11Z DEBUG memberuser 2019-01-17T11:03:11Z DEBUG memberhost 2019-01-17T11:03:11Z DEBUG sourcehost 2019-01-17T11:03:11Z DEBUG memberservice 2019-01-17T11:03:11Z DEBUG managedby 2019-01-17T11:03:11Z DEBUG memberallowcmd 2019-01-17T11:03:11Z DEBUG memberdenycmd 2019-01-17T11:03:11Z DEBUG ipasudorunas 2019-01-17T11:03:11Z DEBUG ipasudorunasgroup 2019-01-17T11:03:11Z DEBUG ipatokenradiusconfiglink 2019-01-17T11:03:11Z DEBUG ipaassignedidview 2019-01-17T11:03:11Z DEBUG ipaallowedtarget 2019-01-17T11:03:11Z DEBUG ipamemberca 2019-01-17T11:03:11Z DEBUG ipamembercertprofile 2019-01-17T11:03:11Z DEBUG ipalocation 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG referint_postop_init 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Parsing update file '/usr/share/ipa/updates/30-provisioning.update' 2019-01-17T11:03:11Z DEBUG New entry: cn=provisioning,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=provisioning,dc=local 2019-01-17T11:03:11Z DEBUG objectclass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG provisioning 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=provisioning,dc=local 2019-01-17T11:03:11Z DEBUG objectclass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG provisioning 2019-01-17T11:03:11Z DEBUG New entry: cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:11Z DEBUG objectclass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG accounts 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:11Z DEBUG objectclass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG accounts 2019-01-17T11:03:11Z DEBUG New entry: cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:11Z DEBUG objectclass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG staged users 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:11Z DEBUG objectclass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG staged users 2019-01-17T11:03:11Z DEBUG New entry: cn=deleted users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=deleted users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:11Z DEBUG objectclass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG deleted users 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=deleted users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:11Z DEBUG objectclass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG deleted users 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG staged users 2019-01-17T11:03:11Z DEBUG remove: '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=local";)' from aci, current value [] 2019-01-17T11:03:11Z DEBUG remove: '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=local";)' not in aci 2019-01-17T11:03:11Z DEBUG add: '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' to aci, current value [] 2019-01-17T11:03:11Z DEBUG add: updated value [u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG aci: 2019-01-17T11:03:11Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG staged users 2019-01-17T11:03:11Z DEBUG [(2, u'aci', [u'(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'])] 2019-01-17T11:03:11Z DEBUG Updated 1 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=deleted users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=deleted users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG deleted users 2019-01-17T11:03:11Z DEBUG remove: '(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=local";)' from aci, current value [] 2019-01-17T11:03:11Z DEBUG remove: '(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=local";)' not in aci 2019-01-17T11:03:11Z DEBUG add: '(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)' to aci, current value [] 2019-01-17T11:03:11Z DEBUG add: updated value [u'(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:03:11Z DEBUG add: '(targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";)' to aci, current value [u'(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";)'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=deleted users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG aci: 2019-01-17T11:03:11Z DEBUG (targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";) 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG deleted users 2019-01-17T11:03:11Z DEBUG [(2, u'aci', [u'(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";)'])] 2019-01-17T11:03:11Z DEBUG Updated 1 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG New entry: cn=provisioning accounts lock,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=provisioning accounts lock,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG cosSuperDefinition 2019-01-17T11:03:11Z DEBUG cosPointerDefinition 2019-01-17T11:03:11Z DEBUG ldapSubEntry 2019-01-17T11:03:11Z DEBUG costemplatedn: 2019-01-17T11:03:11Z DEBUG cn=Inactivation cos template,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG provisioning accounts lock 2019-01-17T11:03:11Z DEBUG cosAttribute: 2019-01-17T11:03:11Z DEBUG nsaccountlock operational 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=provisioning accounts lock,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG cosSuperDefinition 2019-01-17T11:03:11Z DEBUG cosPointerDefinition 2019-01-17T11:03:11Z DEBUG ldapSubEntry 2019-01-17T11:03:11Z DEBUG costemplatedn: 2019-01-17T11:03:11Z DEBUG cn=Inactivation cos template,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG provisioning accounts lock 2019-01-17T11:03:11Z DEBUG cosAttribute: 2019-01-17T11:03:11Z DEBUG nsaccountlock operational 2019-01-17T11:03:11Z DEBUG New entry: cn=Inactivation cos template,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=Inactivation cos template,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG cosTemplate 2019-01-17T11:03:11Z DEBUG cosPriority: 2019-01-17T11:03:11Z DEBUG 1 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Inactivation cos template 2019-01-17T11:03:11Z DEBUG nsAccountLock: 2019-01-17T11:03:11Z DEBUG true 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=Inactivation cos template,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG cosTemplate 2019-01-17T11:03:11Z DEBUG cosPriority: 2019-01-17T11:03:11Z DEBUG 1 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Inactivation cos template 2019-01-17T11:03:11Z DEBUG nsAccountLock: 2019-01-17T11:03:11Z DEBUG true 2019-01-17T11:03:11Z DEBUG Parsing update file '/usr/share/ipa/updates/30-s4u2proxy.update' 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG s4u2proxy 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG s4u2proxy 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG ipaKrb5DelegationACL 2019-01-17T11:03:11Z DEBUG groupOfPrincipals 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG memberPrincipal: 2019-01-17T11:03:11Z DEBUG HTTP/centos75.local@LOCAL 2019-01-17T11:03:11Z DEBUG ipaAllowedTarget: 2019-01-17T11:03:11Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipa-http-delegation 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG ipaKrb5DelegationACL 2019-01-17T11:03:11Z DEBUG groupOfPrincipals 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG memberPrincipal: 2019-01-17T11:03:11Z DEBUG HTTP/centos75.local@LOCAL 2019-01-17T11:03:11Z DEBUG ipaAllowedTarget: 2019-01-17T11:03:11Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipa-http-delegation 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG groupOfPrincipals 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG memberPrincipal: 2019-01-17T11:03:11Z DEBUG ldap/centos75.local@LOCAL 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipa-ldap-delegation-targets 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG groupOfPrincipals 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG memberPrincipal: 2019-01-17T11:03:11Z DEBUG ldap/centos75.local@LOCAL 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipa-ldap-delegation-targets 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG ipaKrb5DelegationACL 2019-01-17T11:03:11Z DEBUG groupOfPrincipals 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG memberPrincipal: 2019-01-17T11:03:11Z DEBUG HTTP/centos75.local@LOCAL 2019-01-17T11:03:11Z DEBUG ipaAllowedTarget: 2019-01-17T11:03:11Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipa-http-delegation 2019-01-17T11:03:11Z DEBUG add: 'HTTP/centos75.local@LOCAL' to memberPrincipal, current value [u'HTTP/centos75.local@LOCAL'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'HTTP/centos75.local@LOCAL'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG ipaKrb5DelegationACL 2019-01-17T11:03:11Z DEBUG groupOfPrincipals 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG memberPrincipal: 2019-01-17T11:03:11Z DEBUG HTTP/centos75.local@LOCAL 2019-01-17T11:03:11Z DEBUG ipaAllowedTarget: 2019-01-17T11:03:11Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipa-http-delegation 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG groupOfPrincipals 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG memberPrincipal: 2019-01-17T11:03:11Z DEBUG ldap/centos75.local@LOCAL 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipa-ldap-delegation-targets 2019-01-17T11:03:11Z DEBUG add: 'ldap/centos75.local@LOCAL' to memberPrincipal, current value [u'ldap/centos75.local@LOCAL'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'ldap/centos75.local@LOCAL'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG groupOfPrincipals 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG memberPrincipal: 2019-01-17T11:03:11Z DEBUG ldap/centos75.local@LOCAL 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipa-ldap-delegation-targets 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Parsing update file '/usr/share/ipa/updates/37-locations.update' 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=locations,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=locations,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG locations 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=locations,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG locations 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Parsing update file '/usr/share/ipa/updates/40-automember.update' 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=Auto Membership Plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG Auto Membership 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Auto Membership Plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG Auto Membership plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libautomember-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginConfigArea: 2019-01-17T11:03:11Z DEBUG cn=automember,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG betxnpreoperation 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG automember_init 2019-01-17T11:03:11Z DEBUG addifnew: 'cn=automember,cn=etc,dc=local' to nsslapd-pluginConfigArea, current value [u'cn=automember,cn=etc,dc=local'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:11Z DEBUG Auto Membership 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Auto Membership Plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:11Z DEBUG 1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:11Z DEBUG Auto Membership plugin 2019-01-17T11:03:11Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:11Z DEBUG libautomember-plugin 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsSlapdPlugin 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:11Z DEBUG database 2019-01-17T11:03:11Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:11Z DEBUG 389 Project 2019-01-17T11:03:11Z DEBUG nsslapd-pluginConfigArea: 2019-01-17T11:03:11Z DEBUG cn=automember,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:11Z DEBUG betxnpreoperation 2019-01-17T11:03:11Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:11Z DEBUG automember_init 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=automember,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=automember,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG aci: 2019-01-17T11:03:11Z DEBUG (targetattr = "automemberdefaultgroup || automemberdisabled || automemberfilter || automembergroupingattr || automemberscope || cn || createtimestamp || entryusn || modifytimestamp || objectclass")(targetfilter = "(objectclass=automemberdefinition)")(version 3.0;acl "permission:System: Read Automember Definitions";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Automember Definitions,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "automemberexclusiveregex || automemberinclusiveregex || automembertargetgroup || cn || createtimestamp || description || entryusn || modifytimestamp || objectclass")(targetfilter = "(objectclass=automemberregexrule)")(version 3.0;acl "permission:System: Read Automember Rules";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Automember Rules,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG automember 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=automember,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG aci: 2019-01-17T11:03:11Z DEBUG (targetattr = "automemberdefaultgroup || automemberdisabled || automemberfilter || automembergroupingattr || automemberscope || cn || createtimestamp || entryusn || modifytimestamp || objectclass")(targetfilter = "(objectclass=automemberdefinition)")(version 3.0;acl "permission:System: Read Automember Definitions";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Automember Definitions,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "automemberexclusiveregex || automemberinclusiveregex || automembertargetgroup || cn || createtimestamp || description || entryusn || modifytimestamp || objectclass")(targetfilter = "(objectclass=automemberregexrule)")(version 3.0;acl "permission:System: Read Automember Rules";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Automember Rules,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG automember 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=Hostgroup,cn=automember,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=Hostgroup,cn=automember,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG autoMemberDefinition 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG autoMemberGroupingAttr: 2019-01-17T11:03:11Z DEBUG member:dn 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Hostgroup 2019-01-17T11:03:11Z DEBUG autoMemberScope: 2019-01-17T11:03:11Z DEBUG cn=computers,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG autoMemberFilter: 2019-01-17T11:03:11Z DEBUG objectclass=ipaHost 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=Hostgroup,cn=automember,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG autoMemberDefinition 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG autoMemberGroupingAttr: 2019-01-17T11:03:11Z DEBUG member:dn 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Hostgroup 2019-01-17T11:03:11Z DEBUG autoMemberScope: 2019-01-17T11:03:11Z DEBUG cn=computers,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG autoMemberFilter: 2019-01-17T11:03:11Z DEBUG objectclass=ipaHost 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=Group,cn=automember,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=Group,cn=automember,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG autoMemberDefinition 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG autoMemberGroupingAttr: 2019-01-17T11:03:11Z DEBUG member:dn 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Group 2019-01-17T11:03:11Z DEBUG autoMemberScope: 2019-01-17T11:03:11Z DEBUG cn=users,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG autoMemberFilter: 2019-01-17T11:03:11Z DEBUG objectclass=posixAccount 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=Group,cn=automember,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG autoMemberDefinition 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG autoMemberGroupingAttr: 2019-01-17T11:03:11Z DEBUG member:dn 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Group 2019-01-17T11:03:11Z DEBUG autoMemberScope: 2019-01-17T11:03:11Z DEBUG cn=users,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG autoMemberFilter: 2019-01-17T11:03:11Z DEBUG objectclass=posixAccount 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Parsing update file '/usr/share/ipa/updates/40-certprofile.update' 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=ca,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=ca,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ca 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=ca,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ca 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=certprofiles,cn=ca,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=certprofiles,cn=ca,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG certprofiles 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=certprofiles,cn=ca,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG certprofiles 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Parsing update file '/usr/share/ipa/updates/40-delegation.update' 2019-01-17T11:03:11Z DEBUG New entry: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG groupofnames 2019-01-17T11:03:11Z DEBUG nestedgroup 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Write IPA Configuration 2019-01-17T11:03:11Z DEBUG description: 2019-01-17T11:03:11Z DEBUG Write IPA Configuration 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG groupofnames 2019-01-17T11:03:11Z DEBUG nestedgroup 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Write IPA Configuration 2019-01-17T11:03:11Z DEBUG description: 2019-01-17T11:03:11Z DEBUG Write IPA Configuration 2019-01-17T11:03:11Z DEBUG New entry: cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG groupofnames 2019-01-17T11:03:11Z DEBUG ipapermission 2019-01-17T11:03:11Z DEBUG member: 2019-01-17T11:03:11Z DEBUG cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Write IPA Configuration 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG groupofnames 2019-01-17T11:03:11Z DEBUG ipapermission 2019-01-17T11:03:11Z DEBUG member: 2019-01-17T11:03:11Z DEBUG cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Write IPA Configuration 2019-01-17T11:03:11Z DEBUG Updating existing entry: dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: dc=local 2019-01-17T11:03:11Z DEBUG info: 2019-01-17T11:03:11Z DEBUG IPA V2.0 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG domain 2019-01-17T11:03:11Z DEBUG pilotObject 2019-01-17T11:03:11Z DEBUG domainRelatedObject 2019-01-17T11:03:11Z DEBUG nisDomainObject 2019-01-17T11:03:11Z DEBUG associatedDomain: 2019-01-17T11:03:11Z DEBUG local 2019-01-17T11:03:11Z DEBUG dc: 2019-01-17T11:03:11Z DEBUG local 2019-01-17T11:03:11Z DEBUG nisDomain: 2019-01-17T11:03:11Z DEBUG local 2019-01-17T11:03:11Z DEBUG aci: 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2019-01-17T11:03:11Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:11Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:11Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:11Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:11Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:11Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG add: '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: dc=local 2019-01-17T11:03:11Z DEBUG info: 2019-01-17T11:03:11Z DEBUG IPA V2.0 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG domain 2019-01-17T11:03:11Z DEBUG pilotObject 2019-01-17T11:03:11Z DEBUG domainRelatedObject 2019-01-17T11:03:11Z DEBUG nisDomainObject 2019-01-17T11:03:11Z DEBUG associatedDomain: 2019-01-17T11:03:11Z DEBUG local 2019-01-17T11:03:11Z DEBUG dc: 2019-01-17T11:03:11Z DEBUG local 2019-01-17T11:03:11Z DEBUG nisDomain: 2019-01-17T11:03:11Z DEBUG local 2019-01-17T11:03:11Z DEBUG aci: 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2019-01-17T11:03:11Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:11Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:11Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:11Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:11Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:11Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG [(0, u'aci', [u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";)'])] 2019-01-17T11:03:11Z DEBUG Updated 1 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG New entry: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG nestedgroup 2019-01-17T11:03:11Z DEBUG groupofnames 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG HBAC Administrator 2019-01-17T11:03:11Z DEBUG description: 2019-01-17T11:03:11Z DEBUG HBAC Administrator 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG nestedgroup 2019-01-17T11:03:11Z DEBUG groupofnames 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG HBAC Administrator 2019-01-17T11:03:11Z DEBUG description: 2019-01-17T11:03:11Z DEBUG HBAC Administrator 2019-01-17T11:03:11Z DEBUG New entry: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG nestedgroup 2019-01-17T11:03:11Z DEBUG groupofnames 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Sudo Administrator 2019-01-17T11:03:11Z DEBUG description: 2019-01-17T11:03:11Z DEBUG Sudo Administrator 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG nestedgroup 2019-01-17T11:03:11Z DEBUG groupofnames 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Sudo Administrator 2019-01-17T11:03:11Z DEBUG description: 2019-01-17T11:03:11Z DEBUG Sudo Administrator 2019-01-17T11:03:11Z DEBUG New entry: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG nestedgroup 2019-01-17T11:03:11Z DEBUG groupofnames 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Password Policy Administrator 2019-01-17T11:03:11Z DEBUG description: 2019-01-17T11:03:11Z DEBUG Password Policy Administrator 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG nestedgroup 2019-01-17T11:03:11Z DEBUG groupofnames 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Password Policy Administrator 2019-01-17T11:03:11Z DEBUG description: 2019-01-17T11:03:11Z DEBUG Password Policy Administrator 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=Host Enrollment,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=Host Enrollment,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG groupofnames 2019-01-17T11:03:11Z DEBUG nestedgroup 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Host Enrollment 2019-01-17T11:03:11Z DEBUG description: 2019-01-17T11:03:11Z DEBUG Host Enrollment 2019-01-17T11:03:11Z DEBUG add: 'cn=admins,cn=groups,cn=accounts,dc=local' to member, current value [] 2019-01-17T11:03:11Z DEBUG add: updated value [u'cn=admins,cn=groups,cn=accounts,dc=local'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=Host Enrollment,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG groupofnames 2019-01-17T11:03:11Z DEBUG nestedgroup 2019-01-17T11:03:11Z DEBUG member: 2019-01-17T11:03:11Z DEBUG cn=admins,cn=groups,cn=accounts,dc=local 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Host Enrollment 2019-01-17T11:03:11Z DEBUG description: 2019-01-17T11:03:11Z DEBUG Host Enrollment 2019-01-17T11:03:11Z DEBUG [(2, u'member', [u'cn=admins,cn=groups,cn=accounts,dc=local'])] 2019-01-17T11:03:11Z DEBUG Updated 1 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: dc=local 2019-01-17T11:03:11Z DEBUG info: 2019-01-17T11:03:11Z DEBUG IPA V2.0 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG domain 2019-01-17T11:03:11Z DEBUG pilotObject 2019-01-17T11:03:11Z DEBUG domainRelatedObject 2019-01-17T11:03:11Z DEBUG nisDomainObject 2019-01-17T11:03:11Z DEBUG associatedDomain: 2019-01-17T11:03:11Z DEBUG local 2019-01-17T11:03:11Z DEBUG dc: 2019-01-17T11:03:11Z DEBUG local 2019-01-17T11:03:11Z DEBUG nisDomain: 2019-01-17T11:03:11Z DEBUG local 2019-01-17T11:03:11Z DEBUG aci: 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2019-01-17T11:03:11Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:11Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:11Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:11Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:11Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:11Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG remove: '(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "Add DNS entries";allow (add) groupdn = "ldap:///cn=add dns entries,cn=permissions,cn=pbac,dc=local";)' from aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:11Z DEBUG remove: '(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "Add DNS entries";allow (add) groupdn = "ldap:///cn=add dns entries,cn=permissions,cn=pbac,dc=local";)' not in aci 2019-01-17T11:03:11Z DEBUG remove: '(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "Remove DNS entries";allow (delete) groupdn = "ldap:///cn=remove dns entries,cn=permissions,cn=pbac,dc=local";)' from aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:11Z DEBUG remove: '(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "Remove DNS entries";allow (delete) groupdn = "ldap:///cn=remove dns entries,cn=permissions,cn=pbac,dc=local";)' not in aci 2019-01-17T11:03:11Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy")(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "Update DNS entries";allow (write) groupdn = "ldap:///cn=update dns entries,cn=permissions,cn=pbac,dc=local";)' from aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:11Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy")(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "Update DNS entries";allow (write) groupdn = "ldap:///cn=update dns entries,cn=permissions,cn=pbac,dc=local";)' not in aci 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: dc=local 2019-01-17T11:03:11Z DEBUG info: 2019-01-17T11:03:11Z DEBUG IPA V2.0 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG domain 2019-01-17T11:03:11Z DEBUG pilotObject 2019-01-17T11:03:11Z DEBUG domainRelatedObject 2019-01-17T11:03:11Z DEBUG nisDomainObject 2019-01-17T11:03:11Z DEBUG associatedDomain: 2019-01-17T11:03:11Z DEBUG local 2019-01-17T11:03:11Z DEBUG dc: 2019-01-17T11:03:11Z DEBUG local 2019-01-17T11:03:11Z DEBUG nisDomain: 2019-01-17T11:03:11Z DEBUG local 2019-01-17T11:03:11Z DEBUG aci: 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2019-01-17T11:03:11Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:11Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:11Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:11Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:11Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:11Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG New entry: cn=SELinux User Map Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=SELinux User Map Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG groupofnames 2019-01-17T11:03:11Z DEBUG nestedgroup 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG SELinux User Map Administrators 2019-01-17T11:03:11Z DEBUG description: 2019-01-17T11:03:11Z DEBUG SELinux User Map Administrators 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=SELinux User Map Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG groupofnames 2019-01-17T11:03:11Z DEBUG nestedgroup 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG SELinux User Map Administrators 2019-01-17T11:03:11Z DEBUG description: 2019-01-17T11:03:11Z DEBUG SELinux User Map Administrators 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=ipa,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=ipa,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG aci: 2019-01-17T11:03:11Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LOCAL,cn=services,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipa 2019-01-17T11:03:11Z DEBUG remove: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) userdn = "ldap:///fqdn=centos75.local,cn=computers,cn=accounts,dc=local";)' from aci, current value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LOCAL,cn=services,cn=accounts,dc=local";)'] 2019-01-17T11:03:11Z DEBUG remove: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) userdn = "ldap:///fqdn=centos75.local,cn=computers,cn=accounts,dc=local";)' not in aci 2019-01-17T11:03:11Z DEBUG remove: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) userdn = "ldap:///fqdn=centos75.local,cn=computers,cn=accounts,dc=local";)' from aci, current value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LOCAL,cn=services,cn=accounts,dc=local";)'] 2019-01-17T11:03:11Z DEBUG remove: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) userdn = "ldap:///fqdn=centos75.local,cn=computers,cn=accounts,dc=local";)' not in aci 2019-01-17T11:03:11Z DEBUG add: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)' to aci, current value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LOCAL,cn=services,cn=accounts,dc=local";)'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LOCAL,cn=services,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)'] 2019-01-17T11:03:11Z DEBUG add: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)' to aci, current value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LOCAL,cn=services,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LOCAL,cn=services,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=ipa,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG aci: 2019-01-17T11:03:11Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LOCAL,cn=services,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipa 2019-01-17T11:03:11Z DEBUG [(0, u'aci', [u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)'])] 2019-01-17T11:03:11Z DEBUG Updated 1 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG groupofnames 2019-01-17T11:03:11Z DEBUG ipapermission 2019-01-17T11:03:11Z DEBUG member: 2019-01-17T11:03:11Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Retrieve Certificates from the CA 2019-01-17T11:03:11Z DEBUG add: 'cn=Host Administrators,cn=privileges,cn=pbac,dc=local' to member, current value [u'cn=Certificate Administrators,cn=privileges,cn=pbac,dc=local'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'cn=Certificate Administrators,cn=privileges,cn=pbac,dc=local', u'cn=Host Administrators,cn=privileges,cn=pbac,dc=local'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG groupofnames 2019-01-17T11:03:11Z DEBUG ipapermission 2019-01-17T11:03:11Z DEBUG member: 2019-01-17T11:03:11Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG cn=Host Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Retrieve Certificates from the CA 2019-01-17T11:03:11Z DEBUG [(0, u'member', [u'cn=Host Administrators,cn=privileges,cn=pbac,dc=local'])] 2019-01-17T11:03:11Z DEBUG Updated 1 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG groupofnames 2019-01-17T11:03:11Z DEBUG ipapermission 2019-01-17T11:03:11Z DEBUG member: 2019-01-17T11:03:11Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Revoke Certificate 2019-01-17T11:03:11Z DEBUG add: 'cn=Host Administrators,cn=privileges,cn=pbac,dc=local' to member, current value [u'cn=Certificate Administrators,cn=privileges,cn=pbac,dc=local'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'cn=Certificate Administrators,cn=privileges,cn=pbac,dc=local', u'cn=Host Administrators,cn=privileges,cn=pbac,dc=local'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG groupofnames 2019-01-17T11:03:11Z DEBUG ipapermission 2019-01-17T11:03:11Z DEBUG member: 2019-01-17T11:03:11Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG cn=Host Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Revoke Certificate 2019-01-17T11:03:11Z DEBUG [(0, u'member', [u'cn=Host Administrators,cn=privileges,cn=pbac,dc=local'])] 2019-01-17T11:03:11Z DEBUG Updated 1 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=ipa,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=ipa,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG aci: 2019-01-17T11:03:11Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LOCAL,cn=services,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipa 2019-01-17T11:03:11Z DEBUG remove: '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=local")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) userdn = "ldap:///fqdn=centos75.local,cn=computers,cn=accounts,dc=local";)' from aci, current value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LOCAL,cn=services,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)'] 2019-01-17T11:03:11Z DEBUG remove: '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=local")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) userdn = "ldap:///fqdn=centos75.local,cn=computers,cn=accounts,dc=local";)' not in aci 2019-01-17T11:03:11Z DEBUG add: '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=local")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)' to aci, current value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LOCAL,cn=services,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LOCAL,cn=services,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)', u'(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)', u'(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=local")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=ipa,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG aci: 2019-01-17T11:03:11Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=local")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@LOCAL,cn=services,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=local")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG ipa 2019-01-17T11:03:11Z DEBUG [(0, u'aci', [u'(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=local")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)'])] 2019-01-17T11:03:11Z DEBUG Updated 1 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=certificates,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=certificates,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG certificates 2019-01-17T11:03:11Z DEBUG remove: '(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) userdn = "ldap:///fqdn=centos75.local,cn=computers,cn=accounts,dc=local";)' from aci, current value [] 2019-01-17T11:03:11Z DEBUG remove: '(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) userdn = "ldap:///fqdn=centos75.local,cn=computers,cn=accounts,dc=local";)' not in aci 2019-01-17T11:03:11Z DEBUG add: '(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)' to aci, current value [] 2019-01-17T11:03:11Z DEBUG add: updated value [u'(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=certificates,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG aci: 2019-01-17T11:03:11Z DEBUG (targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG certificates 2019-01-17T11:03:11Z DEBUG [(2, u'aci', [u'(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)'])] 2019-01-17T11:03:11Z DEBUG Updated 1 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG New entry: cn=Automember Task Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=Automember Task Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG nestedgroup 2019-01-17T11:03:11Z DEBUG groupofnames 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Automember Task Administrator 2019-01-17T11:03:11Z DEBUG description: 2019-01-17T11:03:11Z DEBUG Automember Task Administrator 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=Automember Task Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG nestedgroup 2019-01-17T11:03:11Z DEBUG groupofnames 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Automember Task Administrator 2019-01-17T11:03:11Z DEBUG description: 2019-01-17T11:03:11Z DEBUG Automember Task Administrator 2019-01-17T11:03:11Z DEBUG New entry: cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG groupofnames 2019-01-17T11:03:11Z DEBUG ipapermission 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG member: 2019-01-17T11:03:11Z DEBUG cn=Automember Task Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG ipapermissiontype: 2019-01-17T11:03:11Z DEBUG SYSTEM 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Add Automember Rebuild Membership Task 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG groupofnames 2019-01-17T11:03:11Z DEBUG ipapermission 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG member: 2019-01-17T11:03:11Z DEBUG cn=Automember Task Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG ipapermissiontype: 2019-01-17T11:03:11Z DEBUG SYSTEM 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Add Automember Rebuild Membership Task 2019-01-17T11:03:11Z DEBUG Updating existing entry: cn=config 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-betype: 2019-01-17T11:03:11Z DEBUG ldbm database 2019-01-17T11:03:11Z DEBUG nsslapd-nagle: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:03:11Z DEBUG 2019-01-17T11:03:11Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:03:11Z DEBUG 100 2019-01-17T11:03:11Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-referralmode: 2019-01-17T11:03:11Z DEBUG 2019-01-17T11:03:11Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:03:11Z DEBUG 5 2019-01-17T11:03:11Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:03:11Z DEBUG 64 2019-01-17T11:03:11Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:03:11Z DEBUG 500 2019-01-17T11:03:11Z DEBUG passwordMinAlphas: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-readonly: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG passwordLegacyPolicy: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:03:11Z DEBUG allowed 2019-01-17T11:03:11Z DEBUG passwordMinUppers: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-plugin: 2019-01-17T11:03:11Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:03:11Z DEBUG 1 2019-01-17T11:03:11Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:03:11Z DEBUG 2097152 2019-01-17T11:03:11Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:03:11Z DEBUG 20971520 2019-01-17T11:03:11Z DEBUG nsslapd-timelimit: 2019-01-17T11:03:11Z DEBUG 3600 2019-01-17T11:03:11Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG passwordMinTokenLength: 2019-01-17T11:03:11Z DEBUG 3 2019-01-17T11:03:11Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:03:11Z DEBUG -10 2019-01-17T11:03:11Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:03:11Z DEBUG week 2019-01-17T11:03:11Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:03:11Z DEBUG 1 2019-01-17T11:03:11Z DEBUG passwordMinAge: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:03:11Z DEBUG 1 2019-01-17T11:03:11Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:03:11Z DEBUG week 2019-01-17T11:03:11Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:03:11Z DEBUG 60 2019-01-17T11:03:11Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:03:11Z DEBUG 1024 2019-01-17T11:03:11Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG passwordInHistory: 2019-01-17T11:03:11Z DEBUG 6 2019-01-17T11:03:11Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-conntablesize: 2019-01-17T11:03:11Z DEBUG 16384 2019-01-17T11:03:11Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:03:11Z DEBUG month 2019-01-17T11:03:11Z DEBUG nsslapd-saslpath: 2019-01-17T11:03:11Z DEBUG 2019-01-17T11:03:11Z DEBUG passwordMaxAge: 2019-01-17T11:03:11Z DEBUG 8640000 2019-01-17T11:03:11Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:03:11Z DEBUG 5 2019-01-17T11:03:11Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:03:11Z DEBUG gidNumber 2019-01-17T11:03:11Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:03:11Z DEBUG 1 2019-01-17T11:03:11Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:03:11Z DEBUG day 2019-01-17T11:03:11Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-csnlogging: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-tmpdir: 2019-01-17T11:03:11Z DEBUG /tmp 2019-01-17T11:03:11Z DEBUG passwordResetFailureCount: 2019-01-17T11:03:11Z DEBUG 600 2019-01-17T11:03:11Z DEBUG nsslapd-counters: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-svrtab: 2019-01-17T11:03:11Z DEBUG 2019-01-17T11:03:11Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:03:11Z DEBUG 2019-01-17T11:03:11Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:03:11Z DEBUG month 2019-01-17T11:03:11Z DEBUG nsslapd-minssf: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:03:11Z DEBUG 100 2019-01-17T11:03:11Z DEBUG nsslapd-schemadir: 2019-01-17T11:03:11Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:03:11Z DEBUG nsslapd-localuser: 2019-01-17T11:03:11Z DEBUG dirsrv 2019-01-17T11:03:11Z DEBUG nsslapd-security: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG passwordChange: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:03:11Z DEBUG cn=config:nsslapd-port 2019-01-17T11:03:11Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:03:11Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:03:11Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:03:11Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:03:11Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:03:11Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:03:11Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:03:11Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:03:11Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:03:11Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:03:11Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:03:11Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:03:11Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:03:11Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:03:11Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:03:11Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:03:11Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:03:11Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:03:11Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:03:11Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:03:11Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:03:11Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:03:11Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:03:11Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:03:11Z DEBUG passwordMaxFailure: 2019-01-17T11:03:11Z DEBUG 3 2019-01-17T11:03:11Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:03:11Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:03:11Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:03:11Z DEBUG 1 2019-01-17T11:03:11Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:03:11Z DEBUG 128 2019-01-17T11:03:11Z DEBUG nsslapd-accesslog: 2019-01-17T11:03:11Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:03:11Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:03:11Z DEBUG 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-rootdn: 2019-01-17T11:03:11Z DEBUG cn=Directory Manager 2019-01-17T11:03:11Z DEBUG nsslapd-ldifdir: 2019-01-17T11:03:11Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:03:11Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:03:11Z DEBUG 600 2019-01-17T11:03:11Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:03:11Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:03:11Z DEBUG 1 2019-01-17T11:03:11Z DEBUG passwordMustChange: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG passwordExp: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:03:11Z DEBUG 2019-01-17T11:03:11Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:03:11Z DEBUG 5 2019-01-17T11:03:11Z DEBUG nsslapd-logging-backend: 2019-01-17T11:03:11Z DEBUG dirsrv-log 2019-01-17T11:03:11Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:03:11Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:11Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG aci: 2019-01-17T11:03:11Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:03:11Z DEBUG 100 2019-01-17T11:03:11Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:03:11Z DEBUG cn=Directory Manager 2019-01-17T11:03:11Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG passwordMinLength: 2019-01-17T11:03:11Z DEBUG 8 2019-01-17T11:03:11Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-idletimeout: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:03:11Z DEBUG -10 2019-01-17T11:03:11Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:03:11Z DEBUG week 2019-01-17T11:03:11Z DEBUG nsslapd-securePort: 2019-01-17T11:03:11Z DEBUG 636 2019-01-17T11:03:11Z DEBUG nsslapd-snmp-index: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG config 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapdConfig 2019-01-17T11:03:11Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG passwordSendExpiringTime: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-hash-filters: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:03:11Z DEBUG next 2019-01-17T11:03:11Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:03:11Z DEBUG -10 2019-01-17T11:03:11Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:03:11Z DEBUG 5 2019-01-17T11:03:11Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:03:11Z DEBUG 1 2019-01-17T11:03:11Z DEBUG nsslapd-listenhost: 2019-01-17T11:03:11Z DEBUG 2019-01-17T11:03:11Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:03:11Z DEBUG 600 2019-01-17T11:03:11Z DEBUG nsslapd-errorlog: 2019-01-17T11:03:11Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:03:11Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG passwordCheckSyntax: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG passwordGraceLimit: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG passwordWarning: 2019-01-17T11:03:11Z DEBUG 86400 2019-01-17T11:03:11Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:03:11Z DEBUG 600 2019-01-17T11:03:11Z DEBUG nsslapd-instancedir: 2019-01-17T11:03:11Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:03:11Z DEBUG nsslapd-config: 2019-01-17T11:03:11Z DEBUG cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:03:11Z DEBUG 100 2019-01-17T11:03:11Z DEBUG nsslapd-versionstring: 2019-01-17T11:03:11Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:03:11Z DEBUG 256 2019-01-17T11:03:11Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:03:11Z DEBUG 2097152 2019-01-17T11:03:11Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:03:11Z DEBUG month 2019-01-17T11:03:11Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:03:11Z DEBUG SSHA512 2019-01-17T11:03:11Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:03:11Z DEBUG 1 2019-01-17T11:03:11Z DEBUG passwordLockout: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-lockdir: 2019-01-17T11:03:11Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:03:11Z DEBUG nsslapd-certdir: 2019-01-17T11:03:11Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:03:11Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:03:11Z DEBUG 10 2019-01-17T11:03:11Z DEBUG nsslapd-backendconfig: 2019-01-17T11:03:11Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-threadnumber: 2019-01-17T11:03:11Z DEBUG 24 2019-01-17T11:03:11Z DEBUG nsslapd-schemamod: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-localhost: 2019-01-17T11:03:11Z DEBUG centos75.local 2019-01-17T11:03:11Z DEBUG nsslapd-bakdir: 2019-01-17T11:03:11Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:03:11Z DEBUG passwordMin8bit: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:03:11Z DEBUG uidNumber 2019-01-17T11:03:11Z DEBUG nsslapd-validate-cert: 2019-01-17T11:03:11Z DEBUG warn 2019-01-17T11:03:11Z DEBUG passwordMinCategories: 2019-01-17T11:03:11Z DEBUG 3 2019-01-17T11:03:11Z DEBUG passwordMinLowers: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG passwordAdminDN: 2019-01-17T11:03:11Z DEBUG 2019-01-17T11:03:11Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG passwordMinSpecials: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:03:11Z DEBUG 100 2019-01-17T11:03:11Z DEBUG nsslapd-lastmod: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:03:11Z DEBUG 40 2019-01-17T11:03:11Z DEBUG passwordMaxRepeats: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:03:11Z DEBUG 2019-01-17T11:03:11Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:03:11Z DEBUG -1 2019-01-17T11:03:11Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:03:11Z DEBUG none 2019-01-17T11:03:11Z DEBUG nsslapd-result-tweak: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:03:11Z DEBUG month 2019-01-17T11:03:11Z DEBUG passwordUnlock: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-schemacheck: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-maxbersize: 2019-01-17T11:03:11Z DEBUG 209715200 2019-01-17T11:03:11Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:03:11Z DEBUG 100 2019-01-17T11:03:11Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:03:11Z DEBUG dc=example,dc=com 2019-01-17T11:03:11Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:03:11Z DEBUG 1 2019-01-17T11:03:11Z DEBUG nsslapd-localssf: 2019-01-17T11:03:11Z DEBUG 71 2019-01-17T11:03:11Z DEBUG nsslapd-sizelimit: 2019-01-17T11:03:11Z DEBUG 2000 2019-01-17T11:03:11Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:03:11Z DEBUG 1 2019-01-17T11:03:11Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:03:11Z DEBUG dc=local 2019-01-17T11:03:11Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:03:11Z DEBUG 1 2019-01-17T11:03:11Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:03:11Z DEBUG 2097152 2019-01-17T11:03:11Z DEBUG passwordLockoutDuration: 2019-01-17T11:03:11Z DEBUG 3600 2019-01-17T11:03:11Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:03:11Z DEBUG 2019-01-17T11:03:11Z DEBUG nsslapd-port: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:03:11Z DEBUG 100 2019-01-17T11:03:11Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:03:11Z DEBUG cn=schema 2019-01-17T11:03:11Z DEBUG 2019-01-17T11:03:11Z DEBUG cn=monitor 2019-01-17T11:03:11Z DEBUG cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:03:11Z DEBUG 1 2019-01-17T11:03:11Z DEBUG nsslapd-auditlog: 2019-01-17T11:03:11Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:11Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:03:11Z DEBUG 600 2019-01-17T11:03:11Z DEBUG nsslapd-rootpw: 2019-01-17T11:03:11Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:03:11Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:03:11Z DEBUG 300000 2019-01-17T11:03:11Z DEBUG nsslapd-workingdir: 2019-01-17T11:03:11Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:03:11Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:03:11Z DEBUG 2019-01-17T11:03:11Z DEBUG nsslapd-rundir: 2019-01-17T11:03:11Z DEBUG /var/run/dirsrv 2019-01-17T11:03:11Z DEBUG nsslapd-schemareplace: 2019-01-17T11:03:11Z DEBUG replication-only 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:03:11Z DEBUG 16384 2019-01-17T11:03:11Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:03:11Z DEBUG 10000 2019-01-17T11:03:11Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG passwordMinDigits: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:03:11Z DEBUG 5 2019-01-17T11:03:11Z DEBUG passwordStorageScheme: 2019-01-17T11:03:11Z DEBUG SSHA512 2019-01-17T11:03:11Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG add: '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";)' to aci, current value [u'(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";)', u'(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";)', u'(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";)', u'(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-betype: 2019-01-17T11:03:11Z DEBUG ldbm database 2019-01-17T11:03:11Z DEBUG nsslapd-nagle: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:03:11Z DEBUG 2019-01-17T11:03:11Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:03:11Z DEBUG 100 2019-01-17T11:03:11Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-referralmode: 2019-01-17T11:03:11Z DEBUG 2019-01-17T11:03:11Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:03:11Z DEBUG 5 2019-01-17T11:03:11Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:03:11Z DEBUG 64 2019-01-17T11:03:11Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:03:11Z DEBUG 500 2019-01-17T11:03:11Z DEBUG passwordMinAlphas: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-readonly: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG passwordLegacyPolicy: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:03:11Z DEBUG allowed 2019-01-17T11:03:11Z DEBUG passwordMinUppers: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-plugin: 2019-01-17T11:03:11Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:03:11Z DEBUG 1 2019-01-17T11:03:11Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:03:11Z DEBUG 2097152 2019-01-17T11:03:11Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:03:11Z DEBUG 20971520 2019-01-17T11:03:11Z DEBUG nsslapd-timelimit: 2019-01-17T11:03:11Z DEBUG 3600 2019-01-17T11:03:11Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG passwordMinTokenLength: 2019-01-17T11:03:11Z DEBUG 3 2019-01-17T11:03:11Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:03:11Z DEBUG -10 2019-01-17T11:03:11Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:03:11Z DEBUG week 2019-01-17T11:03:11Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:03:11Z DEBUG 1 2019-01-17T11:03:11Z DEBUG passwordMinAge: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:03:11Z DEBUG 1 2019-01-17T11:03:11Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:03:11Z DEBUG week 2019-01-17T11:03:11Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:03:11Z DEBUG 60 2019-01-17T11:03:11Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:03:11Z DEBUG 1024 2019-01-17T11:03:11Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG passwordInHistory: 2019-01-17T11:03:11Z DEBUG 6 2019-01-17T11:03:11Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-conntablesize: 2019-01-17T11:03:11Z DEBUG 16384 2019-01-17T11:03:11Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:03:11Z DEBUG month 2019-01-17T11:03:11Z DEBUG nsslapd-saslpath: 2019-01-17T11:03:11Z DEBUG 2019-01-17T11:03:11Z DEBUG passwordMaxAge: 2019-01-17T11:03:11Z DEBUG 8640000 2019-01-17T11:03:11Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:03:11Z DEBUG 5 2019-01-17T11:03:11Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:03:11Z DEBUG gidNumber 2019-01-17T11:03:11Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:03:11Z DEBUG 1 2019-01-17T11:03:11Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:03:11Z DEBUG day 2019-01-17T11:03:11Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-csnlogging: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-tmpdir: 2019-01-17T11:03:11Z DEBUG /tmp 2019-01-17T11:03:11Z DEBUG passwordResetFailureCount: 2019-01-17T11:03:11Z DEBUG 600 2019-01-17T11:03:11Z DEBUG nsslapd-counters: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-svrtab: 2019-01-17T11:03:11Z DEBUG 2019-01-17T11:03:11Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:03:11Z DEBUG 2019-01-17T11:03:11Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:03:11Z DEBUG month 2019-01-17T11:03:11Z DEBUG nsslapd-minssf: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:03:11Z DEBUG 100 2019-01-17T11:03:11Z DEBUG nsslapd-schemadir: 2019-01-17T11:03:11Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:03:11Z DEBUG nsslapd-localuser: 2019-01-17T11:03:11Z DEBUG dirsrv 2019-01-17T11:03:11Z DEBUG nsslapd-security: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG passwordChange: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:03:11Z DEBUG cn=config:nsslapd-port 2019-01-17T11:03:11Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:03:11Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:03:11Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:03:11Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:03:11Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:03:11Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:03:11Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:03:11Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:03:11Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:03:11Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:03:11Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:03:11Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:03:11Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:03:11Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:03:11Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:03:11Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:03:11Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:03:11Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:03:11Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:03:11Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:03:11Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:03:11Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:03:11Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:03:11Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:03:11Z DEBUG passwordMaxFailure: 2019-01-17T11:03:11Z DEBUG 3 2019-01-17T11:03:11Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:03:11Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:03:11Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:03:11Z DEBUG 1 2019-01-17T11:03:11Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:03:11Z DEBUG 128 2019-01-17T11:03:11Z DEBUG nsslapd-accesslog: 2019-01-17T11:03:11Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:03:11Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:03:11Z DEBUG 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-rootdn: 2019-01-17T11:03:11Z DEBUG cn=Directory Manager 2019-01-17T11:03:11Z DEBUG nsslapd-ldifdir: 2019-01-17T11:03:11Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:03:11Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:03:11Z DEBUG 600 2019-01-17T11:03:11Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:03:11Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:03:11Z DEBUG 1 2019-01-17T11:03:11Z DEBUG passwordMustChange: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG passwordExp: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:03:11Z DEBUG 2019-01-17T11:03:11Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:03:11Z DEBUG 5 2019-01-17T11:03:11Z DEBUG nsslapd-logging-backend: 2019-01-17T11:03:11Z DEBUG dirsrv-log 2019-01-17T11:03:11Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:03:11Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:11Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG aci: 2019-01-17T11:03:11Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:03:11Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:03:11Z DEBUG 100 2019-01-17T11:03:11Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:03:11Z DEBUG cn=Directory Manager 2019-01-17T11:03:11Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG passwordMinLength: 2019-01-17T11:03:11Z DEBUG 8 2019-01-17T11:03:11Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-idletimeout: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:03:11Z DEBUG -10 2019-01-17T11:03:11Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:03:11Z DEBUG week 2019-01-17T11:03:11Z DEBUG nsslapd-securePort: 2019-01-17T11:03:11Z DEBUG 636 2019-01-17T11:03:11Z DEBUG nsslapd-snmp-index: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG config 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG extensibleObject 2019-01-17T11:03:11Z DEBUG nsslapdConfig 2019-01-17T11:03:11Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG passwordSendExpiringTime: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-hash-filters: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:03:11Z DEBUG next 2019-01-17T11:03:11Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:03:11Z DEBUG -10 2019-01-17T11:03:11Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:03:11Z DEBUG 5 2019-01-17T11:03:11Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:03:11Z DEBUG 1 2019-01-17T11:03:11Z DEBUG nsslapd-listenhost: 2019-01-17T11:03:11Z DEBUG 2019-01-17T11:03:11Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:03:11Z DEBUG 600 2019-01-17T11:03:11Z DEBUG nsslapd-errorlog: 2019-01-17T11:03:11Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:03:11Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG passwordCheckSyntax: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG passwordGraceLimit: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG passwordWarning: 2019-01-17T11:03:11Z DEBUG 86400 2019-01-17T11:03:11Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:03:11Z DEBUG 600 2019-01-17T11:03:11Z DEBUG nsslapd-instancedir: 2019-01-17T11:03:11Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:03:11Z DEBUG nsslapd-config: 2019-01-17T11:03:11Z DEBUG cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:03:11Z DEBUG 100 2019-01-17T11:03:11Z DEBUG nsslapd-versionstring: 2019-01-17T11:03:11Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:03:11Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:03:11Z DEBUG 256 2019-01-17T11:03:11Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:03:11Z DEBUG 2097152 2019-01-17T11:03:11Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:03:11Z DEBUG month 2019-01-17T11:03:11Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:03:11Z DEBUG SSHA512 2019-01-17T11:03:11Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:03:11Z DEBUG 1 2019-01-17T11:03:11Z DEBUG passwordLockout: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-lockdir: 2019-01-17T11:03:11Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:03:11Z DEBUG nsslapd-certdir: 2019-01-17T11:03:11Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:03:11Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:03:11Z DEBUG 10 2019-01-17T11:03:11Z DEBUG nsslapd-backendconfig: 2019-01-17T11:03:11Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-threadnumber: 2019-01-17T11:03:11Z DEBUG 24 2019-01-17T11:03:11Z DEBUG nsslapd-schemamod: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-localhost: 2019-01-17T11:03:11Z DEBUG centos75.local 2019-01-17T11:03:11Z DEBUG nsslapd-bakdir: 2019-01-17T11:03:11Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:03:11Z DEBUG passwordMin8bit: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:03:11Z DEBUG uidNumber 2019-01-17T11:03:11Z DEBUG nsslapd-validate-cert: 2019-01-17T11:03:11Z DEBUG warn 2019-01-17T11:03:11Z DEBUG passwordMinCategories: 2019-01-17T11:03:11Z DEBUG 3 2019-01-17T11:03:11Z DEBUG passwordMinLowers: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG passwordAdminDN: 2019-01-17T11:03:11Z DEBUG 2019-01-17T11:03:11Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG passwordMinSpecials: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:03:11Z DEBUG 100 2019-01-17T11:03:11Z DEBUG nsslapd-lastmod: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:03:11Z DEBUG 40 2019-01-17T11:03:11Z DEBUG passwordMaxRepeats: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:03:11Z DEBUG 2019-01-17T11:03:11Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:03:11Z DEBUG -1 2019-01-17T11:03:11Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:03:11Z DEBUG none 2019-01-17T11:03:11Z DEBUG nsslapd-result-tweak: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:03:11Z DEBUG month 2019-01-17T11:03:11Z DEBUG passwordUnlock: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-schemacheck: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-maxbersize: 2019-01-17T11:03:11Z DEBUG 209715200 2019-01-17T11:03:11Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:03:11Z DEBUG 100 2019-01-17T11:03:11Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:03:11Z DEBUG dc=example,dc=com 2019-01-17T11:03:11Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:03:11Z DEBUG 1 2019-01-17T11:03:11Z DEBUG nsslapd-localssf: 2019-01-17T11:03:11Z DEBUG 71 2019-01-17T11:03:11Z DEBUG nsslapd-sizelimit: 2019-01-17T11:03:11Z DEBUG 2000 2019-01-17T11:03:11Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:03:11Z DEBUG 1 2019-01-17T11:03:11Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:03:11Z DEBUG dc=local 2019-01-17T11:03:11Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:03:11Z DEBUG 1 2019-01-17T11:03:11Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:03:11Z DEBUG 2097152 2019-01-17T11:03:11Z DEBUG passwordLockoutDuration: 2019-01-17T11:03:11Z DEBUG 3600 2019-01-17T11:03:11Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:03:11Z DEBUG 2019-01-17T11:03:11Z DEBUG nsslapd-port: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:03:11Z DEBUG 100 2019-01-17T11:03:11Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:03:11Z DEBUG cn=schema 2019-01-17T11:03:11Z DEBUG 2019-01-17T11:03:11Z DEBUG cn=monitor 2019-01-17T11:03:11Z DEBUG cn=config 2019-01-17T11:03:11Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:03:11Z DEBUG 1 2019-01-17T11:03:11Z DEBUG nsslapd-auditlog: 2019-01-17T11:03:11Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:11Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:03:11Z DEBUG 600 2019-01-17T11:03:11Z DEBUG nsslapd-rootpw: 2019-01-17T11:03:11Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:03:11Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:03:11Z DEBUG 300000 2019-01-17T11:03:11Z DEBUG nsslapd-workingdir: 2019-01-17T11:03:11Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:03:11Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:03:11Z DEBUG 2019-01-17T11:03:11Z DEBUG nsslapd-rundir: 2019-01-17T11:03:11Z DEBUG /var/run/dirsrv 2019-01-17T11:03:11Z DEBUG nsslapd-schemareplace: 2019-01-17T11:03:11Z DEBUG replication-only 2019-01-17T11:03:11Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:03:11Z DEBUG 16384 2019-01-17T11:03:11Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:03:11Z DEBUG 10000 2019-01-17T11:03:11Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:03:11Z DEBUG off 2019-01-17T11:03:11Z DEBUG passwordMinDigits: 2019-01-17T11:03:11Z DEBUG 0 2019-01-17T11:03:11Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:03:11Z DEBUG 5 2019-01-17T11:03:11Z DEBUG passwordStorageScheme: 2019-01-17T11:03:11Z DEBUG SSHA512 2019-01-17T11:03:11Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:03:11Z DEBUG on 2019-01-17T11:03:11Z DEBUG [] 2019-01-17T11:03:11Z DEBUG Updated 0 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG New entry: cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG retrieve certificate 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG retrieve certificate 2019-01-17T11:03:11Z DEBUG New entry: cn=request certificate,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=request certificate,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG request certificate 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=request certificate,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG request certificate 2019-01-17T11:03:11Z DEBUG New entry: cn=request certificate different host,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=request certificate different host,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG request certificate different host 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=request certificate different host,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG request certificate different host 2019-01-17T11:03:11Z DEBUG New entry: cn=certificate status,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=certificate status,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG certificate status 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=certificate status,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG certificate status 2019-01-17T11:03:11Z DEBUG New entry: cn=revoke certificate,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=revoke certificate,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG revoke certificate 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=revoke certificate,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG revoke certificate 2019-01-17T11:03:11Z DEBUG New entry: cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG certificate remove hold 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG certificate remove hold 2019-01-17T11:03:11Z DEBUG New entry: cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG request certificate ignore caacl 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG nsContainer 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG request certificate ignore caacl 2019-01-17T11:03:11Z DEBUG New entry: cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG groupofnames 2019-01-17T11:03:11Z DEBUG ipapermission 2019-01-17T11:03:11Z DEBUG member: 2019-01-17T11:03:11Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Request Certificate ignoring CA ACLs 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG groupofnames 2019-01-17T11:03:11Z DEBUG ipapermission 2019-01-17T11:03:11Z DEBUG member: 2019-01-17T11:03:11Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Request Certificate ignoring CA ACLs 2019-01-17T11:03:11Z DEBUG Updating existing entry: dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: dc=local 2019-01-17T11:03:11Z DEBUG info: 2019-01-17T11:03:11Z DEBUG IPA V2.0 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG domain 2019-01-17T11:03:11Z DEBUG pilotObject 2019-01-17T11:03:11Z DEBUG domainRelatedObject 2019-01-17T11:03:11Z DEBUG nisDomainObject 2019-01-17T11:03:11Z DEBUG associatedDomain: 2019-01-17T11:03:11Z DEBUG local 2019-01-17T11:03:11Z DEBUG dc: 2019-01-17T11:03:11Z DEBUG local 2019-01-17T11:03:11Z DEBUG nisDomain: 2019-01-17T11:03:11Z DEBUG local 2019-01-17T11:03:11Z DEBUG aci: 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2019-01-17T11:03:11Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:11Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:11Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:11Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:11Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:11Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG add: '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:11Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: dc=local 2019-01-17T11:03:11Z DEBUG info: 2019-01-17T11:03:11Z DEBUG IPA V2.0 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG domain 2019-01-17T11:03:11Z DEBUG pilotObject 2019-01-17T11:03:11Z DEBUG domainRelatedObject 2019-01-17T11:03:11Z DEBUG nisDomainObject 2019-01-17T11:03:11Z DEBUG associatedDomain: 2019-01-17T11:03:11Z DEBUG local 2019-01-17T11:03:11Z DEBUG dc: 2019-01-17T11:03:11Z DEBUG local 2019-01-17T11:03:11Z DEBUG nisDomain: 2019-01-17T11:03:11Z DEBUG local 2019-01-17T11:03:11Z DEBUG aci: 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2019-01-17T11:03:11Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:11Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:11Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2019-01-17T11:03:11Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2019-01-17T11:03:11Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:11Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:11Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:11Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:11Z DEBUG [(0, u'aci', [u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local";)'])] 2019-01-17T11:03:11Z DEBUG Updated 1 2019-01-17T11:03:11Z DEBUG Done 2019-01-17T11:03:11Z DEBUG New entry: cn=RBAC Readers,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=RBAC Readers,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG nestedgroup 2019-01-17T11:03:11Z DEBUG groupofnames 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG RBAC Readers 2019-01-17T11:03:11Z DEBUG description: 2019-01-17T11:03:11Z DEBUG Read roles, privileges, permissions and ACIs 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=RBAC Readers,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG nestedgroup 2019-01-17T11:03:11Z DEBUG groupofnames 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG RBAC Readers 2019-01-17T11:03:11Z DEBUG description: 2019-01-17T11:03:11Z DEBUG Read roles, privileges, permissions and ACIs 2019-01-17T11:03:11Z DEBUG New entry: cn=Password Policy Readers,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=Password Policy Readers,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG nestedgroup 2019-01-17T11:03:11Z DEBUG groupofnames 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Password Policy Readers 2019-01-17T11:03:11Z DEBUG description: 2019-01-17T11:03:11Z DEBUG Read password policies 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=Password Policy Readers,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG nestedgroup 2019-01-17T11:03:11Z DEBUG groupofnames 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Password Policy Readers 2019-01-17T11:03:11Z DEBUG description: 2019-01-17T11:03:11Z DEBUG Read password policies 2019-01-17T11:03:11Z DEBUG New entry: cn=Kerberos Ticket Policy Readers,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Initial value 2019-01-17T11:03:11Z DEBUG dn: cn=Kerberos Ticket Policy Readers,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG nestedgroup 2019-01-17T11:03:11Z DEBUG groupofnames 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Kerberos Ticket Policy Readers 2019-01-17T11:03:11Z DEBUG description: 2019-01-17T11:03:11Z DEBUG Read global and per-user Kerberos ticket policy 2019-01-17T11:03:11Z DEBUG --------------------------------------------- 2019-01-17T11:03:11Z DEBUG Final value after applying updates 2019-01-17T11:03:11Z DEBUG dn: cn=Kerberos Ticket Policy Readers,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:11Z DEBUG objectClass: 2019-01-17T11:03:11Z DEBUG nestedgroup 2019-01-17T11:03:11Z DEBUG groupofnames 2019-01-17T11:03:11Z DEBUG top 2019-01-17T11:03:11Z DEBUG cn: 2019-01-17T11:03:11Z DEBUG Kerberos Ticket Policy Readers 2019-01-17T11:03:11Z DEBUG description: 2019-01-17T11:03:11Z DEBUG Read global and per-user Kerberos ticket policy 2019-01-17T11:03:12Z DEBUG New entry: cn=Automember Readers,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=Automember Readers,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Automember Readers 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Read Automember definitions 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=Automember Readers,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Automember Readers 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Read Automember definitions 2019-01-17T11:03:12Z DEBUG New entry: cn=IPA Masters Readers,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=IPA Masters Readers,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG IPA Masters Readers 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Read list of IPA masters 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=IPA Masters Readers,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG IPA Masters Readers 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Read list of IPA masters 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG nsContainer 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG aci: 2019-01-17T11:03:12Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2019-01-17T11:03:12Z DEBUG (targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=local";) 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG masters 2019-01-17T11:03:12Z DEBUG remove: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) userdn = "ldap:///fqdn=centos75.local,cn=computers,cn=accounts,dc=local";)' from aci, current value [u'(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', u'(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=local";)'] 2019-01-17T11:03:12Z DEBUG remove: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) userdn = "ldap:///fqdn=centos75.local,cn=computers,cn=accounts,dc=local";)' not in aci 2019-01-17T11:03:12Z DEBUG remove: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) userdn = "ldap:///fqdn=centos75.local,cn=computers,cn=accounts,dc=local";)' from aci, current value [u'(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', u'(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=local";)'] 2019-01-17T11:03:12Z DEBUG remove: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) userdn = "ldap:///fqdn=centos75.local,cn=computers,cn=accounts,dc=local";)' not in aci 2019-01-17T11:03:12Z DEBUG add: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)' to aci, current value [u'(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', u'(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=local";)'] 2019-01-17T11:03:12Z DEBUG add: updated value [u'(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', u'(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)'] 2019-01-17T11:03:12Z DEBUG add: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)' to aci, current value [u'(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', u'(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)'] 2019-01-17T11:03:12Z DEBUG add: updated value [u'(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', u'(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)'] 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG nsContainer 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG aci: 2019-01-17T11:03:12Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2019-01-17T11:03:12Z DEBUG (targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";) 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG masters 2019-01-17T11:03:12Z DEBUG [(0, u'aci', [u'(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=local";)'])] 2019-01-17T11:03:12Z DEBUG Updated 1 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG New entry: cn=PassSync Service,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=PassSync Service,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG PassSync Service 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG PassSync Service 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=PassSync Service,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG PassSync Service 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG PassSync Service 2019-01-17T11:03:12Z DEBUG New entry: cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG ipapermission 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG ipapermissiontype: 2019-01-17T11:03:12Z DEBUG SYSTEM 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Read PassSync Managers Configuration 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG ipapermission 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG ipapermissiontype: 2019-01-17T11:03:12Z DEBUG SYSTEM 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Read PassSync Managers Configuration 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=config 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-betype: 2019-01-17T11:03:12Z DEBUG ldbm database 2019-01-17T11:03:12Z DEBUG nsslapd-nagle: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-referralmode: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:03:12Z DEBUG 64 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:03:12Z DEBUG 500 2019-01-17T11:03:12Z DEBUG passwordMinAlphas: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-readonly: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordLegacyPolicy: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:03:12Z DEBUG allowed 2019-01-17T11:03:12Z DEBUG passwordMinUppers: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-plugin: 2019-01-17T11:03:12Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:03:12Z DEBUG 2097152 2019-01-17T11:03:12Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:03:12Z DEBUG 20971520 2019-01-17T11:03:12Z DEBUG nsslapd-timelimit: 2019-01-17T11:03:12Z DEBUG 3600 2019-01-17T11:03:12Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordMinTokenLength: 2019-01-17T11:03:12Z DEBUG 3 2019-01-17T11:03:12Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:03:12Z DEBUG -10 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:03:12Z DEBUG week 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG passwordMinAge: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:03:12Z DEBUG week 2019-01-17T11:03:12Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:03:12Z DEBUG 60 2019-01-17T11:03:12Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:03:12Z DEBUG 1024 2019-01-17T11:03:12Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordInHistory: 2019-01-17T11:03:12Z DEBUG 6 2019-01-17T11:03:12Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-conntablesize: 2019-01-17T11:03:12Z DEBUG 16384 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:03:12Z DEBUG month 2019-01-17T11:03:12Z DEBUG nsslapd-saslpath: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG passwordMaxAge: 2019-01-17T11:03:12Z DEBUG 8640000 2019-01-17T11:03:12Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:03:12Z DEBUG gidNumber 2019-01-17T11:03:12Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:03:12Z DEBUG day 2019-01-17T11:03:12Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-csnlogging: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-tmpdir: 2019-01-17T11:03:12Z DEBUG /tmp 2019-01-17T11:03:12Z DEBUG passwordResetFailureCount: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-counters: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-svrtab: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:03:12Z DEBUG month 2019-01-17T11:03:12Z DEBUG nsslapd-minssf: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-schemadir: 2019-01-17T11:03:12Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:03:12Z DEBUG nsslapd-localuser: 2019-01-17T11:03:12Z DEBUG dirsrv 2019-01-17T11:03:12Z DEBUG nsslapd-security: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordChange: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-port 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:03:12Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:03:12Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:03:12Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:03:12Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:03:12Z DEBUG passwordMaxFailure: 2019-01-17T11:03:12Z DEBUG 3 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:03:12Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:03:12Z DEBUG 128 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:03:12Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-rootdn: 2019-01-17T11:03:12Z DEBUG cn=Directory Manager 2019-01-17T11:03:12Z DEBUG nsslapd-ldifdir: 2019-01-17T11:03:12Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:03:12Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG passwordMustChange: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordExp: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG nsslapd-logging-backend: 2019-01-17T11:03:12Z DEBUG dirsrv-log 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:12Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG aci: 2019-01-17T11:03:12Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:03:12Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:03:12Z DEBUG cn=Directory Manager 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordMinLength: 2019-01-17T11:03:12Z DEBUG 8 2019-01-17T11:03:12Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-idletimeout: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:03:12Z DEBUG -10 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:03:12Z DEBUG week 2019-01-17T11:03:12Z DEBUG nsslapd-securePort: 2019-01-17T11:03:12Z DEBUG 636 2019-01-17T11:03:12Z DEBUG nsslapd-snmp-index: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG config 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG extensibleObject 2019-01-17T11:03:12Z DEBUG nsslapdConfig 2019-01-17T11:03:12Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordSendExpiringTime: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-hash-filters: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:03:12Z DEBUG next 2019-01-17T11:03:12Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:03:12Z DEBUG -10 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-listenhost: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordCheckSyntax: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordGraceLimit: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG passwordWarning: 2019-01-17T11:03:12Z DEBUG 86400 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-instancedir: 2019-01-17T11:03:12Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:03:12Z DEBUG nsslapd-config: 2019-01-17T11:03:12Z DEBUG cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-versionstring: 2019-01-17T11:03:12Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:03:12Z DEBUG 256 2019-01-17T11:03:12Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:03:12Z DEBUG 2097152 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:03:12Z DEBUG month 2019-01-17T11:03:12Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:03:12Z DEBUG SSHA512 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG passwordLockout: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-lockdir: 2019-01-17T11:03:12Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:03:12Z DEBUG nsslapd-certdir: 2019-01-17T11:03:12Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:03:12Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:03:12Z DEBUG 10 2019-01-17T11:03:12Z DEBUG nsslapd-backendconfig: 2019-01-17T11:03:12Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-threadnumber: 2019-01-17T11:03:12Z DEBUG 24 2019-01-17T11:03:12Z DEBUG nsslapd-schemamod: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-localhost: 2019-01-17T11:03:12Z DEBUG centos75.local 2019-01-17T11:03:12Z DEBUG nsslapd-bakdir: 2019-01-17T11:03:12Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:03:12Z DEBUG passwordMin8bit: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:03:12Z DEBUG uidNumber 2019-01-17T11:03:12Z DEBUG nsslapd-validate-cert: 2019-01-17T11:03:12Z DEBUG warn 2019-01-17T11:03:12Z DEBUG passwordMinCategories: 2019-01-17T11:03:12Z DEBUG 3 2019-01-17T11:03:12Z DEBUG passwordMinLowers: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordAdminDN: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordMinSpecials: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-lastmod: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:03:12Z DEBUG 40 2019-01-17T11:03:12Z DEBUG passwordMaxRepeats: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:03:12Z DEBUG -1 2019-01-17T11:03:12Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:03:12Z DEBUG none 2019-01-17T11:03:12Z DEBUG nsslapd-result-tweak: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:03:12Z DEBUG month 2019-01-17T11:03:12Z DEBUG passwordUnlock: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-schemacheck: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-maxbersize: 2019-01-17T11:03:12Z DEBUG 209715200 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:03:12Z DEBUG dc=example,dc=com 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-localssf: 2019-01-17T11:03:12Z DEBUG 71 2019-01-17T11:03:12Z DEBUG nsslapd-sizelimit: 2019-01-17T11:03:12Z DEBUG 2000 2019-01-17T11:03:12Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:03:12Z DEBUG dc=local 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:03:12Z DEBUG 2097152 2019-01-17T11:03:12Z DEBUG passwordLockoutDuration: 2019-01-17T11:03:12Z DEBUG 3600 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-port: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:03:12Z DEBUG cn=schema 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG cn=monitor 2019-01-17T11:03:12Z DEBUG cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-rootpw: 2019-01-17T11:03:12Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:03:12Z DEBUG 300000 2019-01-17T11:03:12Z DEBUG nsslapd-workingdir: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-rundir: 2019-01-17T11:03:12Z DEBUG /var/run/dirsrv 2019-01-17T11:03:12Z DEBUG nsslapd-schemareplace: 2019-01-17T11:03:12Z DEBUG replication-only 2019-01-17T11:03:12Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:03:12Z DEBUG 16384 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:03:12Z DEBUG 10000 2019-01-17T11:03:12Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordMinDigits: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG passwordStorageScheme: 2019-01-17T11:03:12Z DEBUG SSHA512 2019-01-17T11:03:12Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG add: '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)' to aci, current value [u'(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";)', u'(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:12Z DEBUG add: updated value [u'(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";)', u'(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-betype: 2019-01-17T11:03:12Z DEBUG ldbm database 2019-01-17T11:03:12Z DEBUG nsslapd-nagle: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-referralmode: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:03:12Z DEBUG 64 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:03:12Z DEBUG 500 2019-01-17T11:03:12Z DEBUG passwordMinAlphas: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-readonly: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordLegacyPolicy: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:03:12Z DEBUG allowed 2019-01-17T11:03:12Z DEBUG passwordMinUppers: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-plugin: 2019-01-17T11:03:12Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:03:12Z DEBUG 2097152 2019-01-17T11:03:12Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:03:12Z DEBUG 20971520 2019-01-17T11:03:12Z DEBUG nsslapd-timelimit: 2019-01-17T11:03:12Z DEBUG 3600 2019-01-17T11:03:12Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordMinTokenLength: 2019-01-17T11:03:12Z DEBUG 3 2019-01-17T11:03:12Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:03:12Z DEBUG -10 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:03:12Z DEBUG week 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG passwordMinAge: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:03:12Z DEBUG week 2019-01-17T11:03:12Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:03:12Z DEBUG 60 2019-01-17T11:03:12Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:03:12Z DEBUG 1024 2019-01-17T11:03:12Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordInHistory: 2019-01-17T11:03:12Z DEBUG 6 2019-01-17T11:03:12Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-conntablesize: 2019-01-17T11:03:12Z DEBUG 16384 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:03:12Z DEBUG month 2019-01-17T11:03:12Z DEBUG nsslapd-saslpath: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG passwordMaxAge: 2019-01-17T11:03:12Z DEBUG 8640000 2019-01-17T11:03:12Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:03:12Z DEBUG gidNumber 2019-01-17T11:03:12Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:03:12Z DEBUG day 2019-01-17T11:03:12Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-csnlogging: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-tmpdir: 2019-01-17T11:03:12Z DEBUG /tmp 2019-01-17T11:03:12Z DEBUG passwordResetFailureCount: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-counters: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-svrtab: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:03:12Z DEBUG month 2019-01-17T11:03:12Z DEBUG nsslapd-minssf: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-schemadir: 2019-01-17T11:03:12Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:03:12Z DEBUG nsslapd-localuser: 2019-01-17T11:03:12Z DEBUG dirsrv 2019-01-17T11:03:12Z DEBUG nsslapd-security: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordChange: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-port 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:03:12Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:03:12Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:03:12Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:03:12Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:03:12Z DEBUG passwordMaxFailure: 2019-01-17T11:03:12Z DEBUG 3 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:03:12Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:03:12Z DEBUG 128 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:03:12Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-rootdn: 2019-01-17T11:03:12Z DEBUG cn=Directory Manager 2019-01-17T11:03:12Z DEBUG nsslapd-ldifdir: 2019-01-17T11:03:12Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:03:12Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG passwordMustChange: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordExp: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG nsslapd-logging-backend: 2019-01-17T11:03:12Z DEBUG dirsrv-log 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:12Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG aci: 2019-01-17T11:03:12Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:03:12Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:03:12Z DEBUG cn=Directory Manager 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordMinLength: 2019-01-17T11:03:12Z DEBUG 8 2019-01-17T11:03:12Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-idletimeout: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:03:12Z DEBUG -10 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:03:12Z DEBUG week 2019-01-17T11:03:12Z DEBUG nsslapd-securePort: 2019-01-17T11:03:12Z DEBUG 636 2019-01-17T11:03:12Z DEBUG nsslapd-snmp-index: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG config 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG extensibleObject 2019-01-17T11:03:12Z DEBUG nsslapdConfig 2019-01-17T11:03:12Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordSendExpiringTime: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-hash-filters: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:03:12Z DEBUG next 2019-01-17T11:03:12Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:03:12Z DEBUG -10 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-listenhost: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordCheckSyntax: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordGraceLimit: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG passwordWarning: 2019-01-17T11:03:12Z DEBUG 86400 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-instancedir: 2019-01-17T11:03:12Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:03:12Z DEBUG nsslapd-config: 2019-01-17T11:03:12Z DEBUG cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-versionstring: 2019-01-17T11:03:12Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:03:12Z DEBUG 256 2019-01-17T11:03:12Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:03:12Z DEBUG 2097152 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:03:12Z DEBUG month 2019-01-17T11:03:12Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:03:12Z DEBUG SSHA512 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG passwordLockout: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-lockdir: 2019-01-17T11:03:12Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:03:12Z DEBUG nsslapd-certdir: 2019-01-17T11:03:12Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:03:12Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:03:12Z DEBUG 10 2019-01-17T11:03:12Z DEBUG nsslapd-backendconfig: 2019-01-17T11:03:12Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-threadnumber: 2019-01-17T11:03:12Z DEBUG 24 2019-01-17T11:03:12Z DEBUG nsslapd-schemamod: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-localhost: 2019-01-17T11:03:12Z DEBUG centos75.local 2019-01-17T11:03:12Z DEBUG nsslapd-bakdir: 2019-01-17T11:03:12Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:03:12Z DEBUG passwordMin8bit: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:03:12Z DEBUG uidNumber 2019-01-17T11:03:12Z DEBUG nsslapd-validate-cert: 2019-01-17T11:03:12Z DEBUG warn 2019-01-17T11:03:12Z DEBUG passwordMinCategories: 2019-01-17T11:03:12Z DEBUG 3 2019-01-17T11:03:12Z DEBUG passwordMinLowers: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordAdminDN: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordMinSpecials: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-lastmod: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:03:12Z DEBUG 40 2019-01-17T11:03:12Z DEBUG passwordMaxRepeats: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:03:12Z DEBUG -1 2019-01-17T11:03:12Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:03:12Z DEBUG none 2019-01-17T11:03:12Z DEBUG nsslapd-result-tweak: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:03:12Z DEBUG month 2019-01-17T11:03:12Z DEBUG passwordUnlock: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-schemacheck: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-maxbersize: 2019-01-17T11:03:12Z DEBUG 209715200 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:03:12Z DEBUG dc=example,dc=com 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-localssf: 2019-01-17T11:03:12Z DEBUG 71 2019-01-17T11:03:12Z DEBUG nsslapd-sizelimit: 2019-01-17T11:03:12Z DEBUG 2000 2019-01-17T11:03:12Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:03:12Z DEBUG dc=local 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:03:12Z DEBUG 2097152 2019-01-17T11:03:12Z DEBUG passwordLockoutDuration: 2019-01-17T11:03:12Z DEBUG 3600 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-port: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:03:12Z DEBUG cn=schema 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG cn=monitor 2019-01-17T11:03:12Z DEBUG cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-rootpw: 2019-01-17T11:03:12Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:03:12Z DEBUG 300000 2019-01-17T11:03:12Z DEBUG nsslapd-workingdir: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-rundir: 2019-01-17T11:03:12Z DEBUG /var/run/dirsrv 2019-01-17T11:03:12Z DEBUG nsslapd-schemareplace: 2019-01-17T11:03:12Z DEBUG replication-only 2019-01-17T11:03:12Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:03:12Z DEBUG 16384 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:03:12Z DEBUG 10000 2019-01-17T11:03:12Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordMinDigits: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG passwordStorageScheme: 2019-01-17T11:03:12Z DEBUG SSHA512 2019-01-17T11:03:12Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG [] 2019-01-17T11:03:12Z DEBUG Updated 0 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG New entry: cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG ipapermission 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG ipapermissiontype: 2019-01-17T11:03:12Z DEBUG SYSTEM 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Modify PassSync Managers Configuration 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG ipapermission 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG ipapermissiontype: 2019-01-17T11:03:12Z DEBUG SYSTEM 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Modify PassSync Managers Configuration 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=config 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-betype: 2019-01-17T11:03:12Z DEBUG ldbm database 2019-01-17T11:03:12Z DEBUG nsslapd-nagle: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-referralmode: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:03:12Z DEBUG 64 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:03:12Z DEBUG 500 2019-01-17T11:03:12Z DEBUG passwordMinAlphas: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-readonly: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordLegacyPolicy: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:03:12Z DEBUG allowed 2019-01-17T11:03:12Z DEBUG passwordMinUppers: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-plugin: 2019-01-17T11:03:12Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:03:12Z DEBUG 2097152 2019-01-17T11:03:12Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:03:12Z DEBUG 20971520 2019-01-17T11:03:12Z DEBUG nsslapd-timelimit: 2019-01-17T11:03:12Z DEBUG 3600 2019-01-17T11:03:12Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordMinTokenLength: 2019-01-17T11:03:12Z DEBUG 3 2019-01-17T11:03:12Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:03:12Z DEBUG -10 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:03:12Z DEBUG week 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG passwordMinAge: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:03:12Z DEBUG week 2019-01-17T11:03:12Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:03:12Z DEBUG 60 2019-01-17T11:03:12Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:03:12Z DEBUG 1024 2019-01-17T11:03:12Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordInHistory: 2019-01-17T11:03:12Z DEBUG 6 2019-01-17T11:03:12Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-conntablesize: 2019-01-17T11:03:12Z DEBUG 16384 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:03:12Z DEBUG month 2019-01-17T11:03:12Z DEBUG nsslapd-saslpath: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG passwordMaxAge: 2019-01-17T11:03:12Z DEBUG 8640000 2019-01-17T11:03:12Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:03:12Z DEBUG gidNumber 2019-01-17T11:03:12Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:03:12Z DEBUG day 2019-01-17T11:03:12Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-csnlogging: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-tmpdir: 2019-01-17T11:03:12Z DEBUG /tmp 2019-01-17T11:03:12Z DEBUG passwordResetFailureCount: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-counters: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-svrtab: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:03:12Z DEBUG month 2019-01-17T11:03:12Z DEBUG nsslapd-minssf: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-schemadir: 2019-01-17T11:03:12Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:03:12Z DEBUG nsslapd-localuser: 2019-01-17T11:03:12Z DEBUG dirsrv 2019-01-17T11:03:12Z DEBUG nsslapd-security: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordChange: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-port 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:03:12Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:03:12Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:03:12Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:03:12Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:03:12Z DEBUG passwordMaxFailure: 2019-01-17T11:03:12Z DEBUG 3 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:03:12Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:03:12Z DEBUG 128 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:03:12Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-rootdn: 2019-01-17T11:03:12Z DEBUG cn=Directory Manager 2019-01-17T11:03:12Z DEBUG nsslapd-ldifdir: 2019-01-17T11:03:12Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:03:12Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG passwordMustChange: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordExp: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG nsslapd-logging-backend: 2019-01-17T11:03:12Z DEBUG dirsrv-log 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:12Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG aci: 2019-01-17T11:03:12Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:03:12Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:03:12Z DEBUG cn=Directory Manager 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordMinLength: 2019-01-17T11:03:12Z DEBUG 8 2019-01-17T11:03:12Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-idletimeout: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:03:12Z DEBUG -10 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:03:12Z DEBUG week 2019-01-17T11:03:12Z DEBUG nsslapd-securePort: 2019-01-17T11:03:12Z DEBUG 636 2019-01-17T11:03:12Z DEBUG nsslapd-snmp-index: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG config 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG extensibleObject 2019-01-17T11:03:12Z DEBUG nsslapdConfig 2019-01-17T11:03:12Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordSendExpiringTime: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-hash-filters: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:03:12Z DEBUG next 2019-01-17T11:03:12Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:03:12Z DEBUG -10 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-listenhost: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordCheckSyntax: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordGraceLimit: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG passwordWarning: 2019-01-17T11:03:12Z DEBUG 86400 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-instancedir: 2019-01-17T11:03:12Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:03:12Z DEBUG nsslapd-config: 2019-01-17T11:03:12Z DEBUG cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-versionstring: 2019-01-17T11:03:12Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:03:12Z DEBUG 256 2019-01-17T11:03:12Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:03:12Z DEBUG 2097152 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:03:12Z DEBUG month 2019-01-17T11:03:12Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:03:12Z DEBUG SSHA512 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG passwordLockout: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-lockdir: 2019-01-17T11:03:12Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:03:12Z DEBUG nsslapd-certdir: 2019-01-17T11:03:12Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:03:12Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:03:12Z DEBUG 10 2019-01-17T11:03:12Z DEBUG nsslapd-backendconfig: 2019-01-17T11:03:12Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-threadnumber: 2019-01-17T11:03:12Z DEBUG 24 2019-01-17T11:03:12Z DEBUG nsslapd-schemamod: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-localhost: 2019-01-17T11:03:12Z DEBUG centos75.local 2019-01-17T11:03:12Z DEBUG nsslapd-bakdir: 2019-01-17T11:03:12Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:03:12Z DEBUG passwordMin8bit: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:03:12Z DEBUG uidNumber 2019-01-17T11:03:12Z DEBUG nsslapd-validate-cert: 2019-01-17T11:03:12Z DEBUG warn 2019-01-17T11:03:12Z DEBUG passwordMinCategories: 2019-01-17T11:03:12Z DEBUG 3 2019-01-17T11:03:12Z DEBUG passwordMinLowers: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordAdminDN: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordMinSpecials: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-lastmod: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:03:12Z DEBUG 40 2019-01-17T11:03:12Z DEBUG passwordMaxRepeats: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:03:12Z DEBUG -1 2019-01-17T11:03:12Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:03:12Z DEBUG none 2019-01-17T11:03:12Z DEBUG nsslapd-result-tweak: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:03:12Z DEBUG month 2019-01-17T11:03:12Z DEBUG passwordUnlock: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-schemacheck: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-maxbersize: 2019-01-17T11:03:12Z DEBUG 209715200 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:03:12Z DEBUG dc=example,dc=com 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-localssf: 2019-01-17T11:03:12Z DEBUG 71 2019-01-17T11:03:12Z DEBUG nsslapd-sizelimit: 2019-01-17T11:03:12Z DEBUG 2000 2019-01-17T11:03:12Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:03:12Z DEBUG dc=local 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:03:12Z DEBUG 2097152 2019-01-17T11:03:12Z DEBUG passwordLockoutDuration: 2019-01-17T11:03:12Z DEBUG 3600 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-port: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:03:12Z DEBUG cn=schema 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG cn=monitor 2019-01-17T11:03:12Z DEBUG cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-rootpw: 2019-01-17T11:03:12Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:03:12Z DEBUG 300000 2019-01-17T11:03:12Z DEBUG nsslapd-workingdir: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-rundir: 2019-01-17T11:03:12Z DEBUG /var/run/dirsrv 2019-01-17T11:03:12Z DEBUG nsslapd-schemareplace: 2019-01-17T11:03:12Z DEBUG replication-only 2019-01-17T11:03:12Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:03:12Z DEBUG 16384 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:03:12Z DEBUG 10000 2019-01-17T11:03:12Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordMinDigits: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG passwordStorageScheme: 2019-01-17T11:03:12Z DEBUG SSHA512 2019-01-17T11:03:12Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG add: '(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)' to aci, current value [u'(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";)', u'(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:12Z DEBUG add: updated value [u'(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";)', u'(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-betype: 2019-01-17T11:03:12Z DEBUG ldbm database 2019-01-17T11:03:12Z DEBUG nsslapd-nagle: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-referralmode: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:03:12Z DEBUG 64 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:03:12Z DEBUG 500 2019-01-17T11:03:12Z DEBUG passwordMinAlphas: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-readonly: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordLegacyPolicy: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:03:12Z DEBUG allowed 2019-01-17T11:03:12Z DEBUG passwordMinUppers: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-plugin: 2019-01-17T11:03:12Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:03:12Z DEBUG 2097152 2019-01-17T11:03:12Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:03:12Z DEBUG 20971520 2019-01-17T11:03:12Z DEBUG nsslapd-timelimit: 2019-01-17T11:03:12Z DEBUG 3600 2019-01-17T11:03:12Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordMinTokenLength: 2019-01-17T11:03:12Z DEBUG 3 2019-01-17T11:03:12Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:03:12Z DEBUG -10 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:03:12Z DEBUG week 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG passwordMinAge: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:03:12Z DEBUG week 2019-01-17T11:03:12Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:03:12Z DEBUG 60 2019-01-17T11:03:12Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:03:12Z DEBUG 1024 2019-01-17T11:03:12Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordInHistory: 2019-01-17T11:03:12Z DEBUG 6 2019-01-17T11:03:12Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-conntablesize: 2019-01-17T11:03:12Z DEBUG 16384 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:03:12Z DEBUG month 2019-01-17T11:03:12Z DEBUG nsslapd-saslpath: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG passwordMaxAge: 2019-01-17T11:03:12Z DEBUG 8640000 2019-01-17T11:03:12Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:03:12Z DEBUG gidNumber 2019-01-17T11:03:12Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:03:12Z DEBUG day 2019-01-17T11:03:12Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-csnlogging: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-tmpdir: 2019-01-17T11:03:12Z DEBUG /tmp 2019-01-17T11:03:12Z DEBUG passwordResetFailureCount: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-counters: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-svrtab: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:03:12Z DEBUG month 2019-01-17T11:03:12Z DEBUG nsslapd-minssf: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-schemadir: 2019-01-17T11:03:12Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:03:12Z DEBUG nsslapd-localuser: 2019-01-17T11:03:12Z DEBUG dirsrv 2019-01-17T11:03:12Z DEBUG nsslapd-security: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordChange: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-port 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:03:12Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:03:12Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:03:12Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:03:12Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:03:12Z DEBUG passwordMaxFailure: 2019-01-17T11:03:12Z DEBUG 3 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:03:12Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:03:12Z DEBUG 128 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:03:12Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-rootdn: 2019-01-17T11:03:12Z DEBUG cn=Directory Manager 2019-01-17T11:03:12Z DEBUG nsslapd-ldifdir: 2019-01-17T11:03:12Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:03:12Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG passwordMustChange: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordExp: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG nsslapd-logging-backend: 2019-01-17T11:03:12Z DEBUG dirsrv-log 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:12Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG aci: 2019-01-17T11:03:12Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:03:12Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:03:12Z DEBUG cn=Directory Manager 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordMinLength: 2019-01-17T11:03:12Z DEBUG 8 2019-01-17T11:03:12Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-idletimeout: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:03:12Z DEBUG -10 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:03:12Z DEBUG week 2019-01-17T11:03:12Z DEBUG nsslapd-securePort: 2019-01-17T11:03:12Z DEBUG 636 2019-01-17T11:03:12Z DEBUG nsslapd-snmp-index: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG config 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG extensibleObject 2019-01-17T11:03:12Z DEBUG nsslapdConfig 2019-01-17T11:03:12Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordSendExpiringTime: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-hash-filters: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:03:12Z DEBUG next 2019-01-17T11:03:12Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:03:12Z DEBUG -10 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-listenhost: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordCheckSyntax: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordGraceLimit: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG passwordWarning: 2019-01-17T11:03:12Z DEBUG 86400 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-instancedir: 2019-01-17T11:03:12Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:03:12Z DEBUG nsslapd-config: 2019-01-17T11:03:12Z DEBUG cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-versionstring: 2019-01-17T11:03:12Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:03:12Z DEBUG 256 2019-01-17T11:03:12Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:03:12Z DEBUG 2097152 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:03:12Z DEBUG month 2019-01-17T11:03:12Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:03:12Z DEBUG SSHA512 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG passwordLockout: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-lockdir: 2019-01-17T11:03:12Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:03:12Z DEBUG nsslapd-certdir: 2019-01-17T11:03:12Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:03:12Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:03:12Z DEBUG 10 2019-01-17T11:03:12Z DEBUG nsslapd-backendconfig: 2019-01-17T11:03:12Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-threadnumber: 2019-01-17T11:03:12Z DEBUG 24 2019-01-17T11:03:12Z DEBUG nsslapd-schemamod: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-localhost: 2019-01-17T11:03:12Z DEBUG centos75.local 2019-01-17T11:03:12Z DEBUG nsslapd-bakdir: 2019-01-17T11:03:12Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:03:12Z DEBUG passwordMin8bit: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:03:12Z DEBUG uidNumber 2019-01-17T11:03:12Z DEBUG nsslapd-validate-cert: 2019-01-17T11:03:12Z DEBUG warn 2019-01-17T11:03:12Z DEBUG passwordMinCategories: 2019-01-17T11:03:12Z DEBUG 3 2019-01-17T11:03:12Z DEBUG passwordMinLowers: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordAdminDN: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordMinSpecials: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-lastmod: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:03:12Z DEBUG 40 2019-01-17T11:03:12Z DEBUG passwordMaxRepeats: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:03:12Z DEBUG -1 2019-01-17T11:03:12Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:03:12Z DEBUG none 2019-01-17T11:03:12Z DEBUG nsslapd-result-tweak: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:03:12Z DEBUG month 2019-01-17T11:03:12Z DEBUG passwordUnlock: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-schemacheck: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-maxbersize: 2019-01-17T11:03:12Z DEBUG 209715200 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:03:12Z DEBUG dc=example,dc=com 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-localssf: 2019-01-17T11:03:12Z DEBUG 71 2019-01-17T11:03:12Z DEBUG nsslapd-sizelimit: 2019-01-17T11:03:12Z DEBUG 2000 2019-01-17T11:03:12Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:03:12Z DEBUG dc=local 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:03:12Z DEBUG 2097152 2019-01-17T11:03:12Z DEBUG passwordLockoutDuration: 2019-01-17T11:03:12Z DEBUG 3600 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-port: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:03:12Z DEBUG cn=schema 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG cn=monitor 2019-01-17T11:03:12Z DEBUG cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-rootpw: 2019-01-17T11:03:12Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:03:12Z DEBUG 300000 2019-01-17T11:03:12Z DEBUG nsslapd-workingdir: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-rundir: 2019-01-17T11:03:12Z DEBUG /var/run/dirsrv 2019-01-17T11:03:12Z DEBUG nsslapd-schemareplace: 2019-01-17T11:03:12Z DEBUG replication-only 2019-01-17T11:03:12Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:03:12Z DEBUG 16384 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:03:12Z DEBUG 10000 2019-01-17T11:03:12Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordMinDigits: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG passwordStorageScheme: 2019-01-17T11:03:12Z DEBUG SSHA512 2019-01-17T11:03:12Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG [] 2019-01-17T11:03:12Z DEBUG Updated 0 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG New entry: cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG ipapermission 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG ipapermissiontype: 2019-01-17T11:03:12Z DEBUG SYSTEM 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Read LDBM Database Configuration 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG ipapermission 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG ipapermissiontype: 2019-01-17T11:03:12Z DEBUG SYSTEM 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Read LDBM Database Configuration 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=config 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-betype: 2019-01-17T11:03:12Z DEBUG ldbm database 2019-01-17T11:03:12Z DEBUG nsslapd-nagle: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-referralmode: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:03:12Z DEBUG 64 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:03:12Z DEBUG 500 2019-01-17T11:03:12Z DEBUG passwordMinAlphas: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-readonly: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordLegacyPolicy: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:03:12Z DEBUG allowed 2019-01-17T11:03:12Z DEBUG passwordMinUppers: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-plugin: 2019-01-17T11:03:12Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:03:12Z DEBUG 2097152 2019-01-17T11:03:12Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:03:12Z DEBUG 20971520 2019-01-17T11:03:12Z DEBUG nsslapd-timelimit: 2019-01-17T11:03:12Z DEBUG 3600 2019-01-17T11:03:12Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordMinTokenLength: 2019-01-17T11:03:12Z DEBUG 3 2019-01-17T11:03:12Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:03:12Z DEBUG -10 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:03:12Z DEBUG week 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG passwordMinAge: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:03:12Z DEBUG week 2019-01-17T11:03:12Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:03:12Z DEBUG 60 2019-01-17T11:03:12Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:03:12Z DEBUG 1024 2019-01-17T11:03:12Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordInHistory: 2019-01-17T11:03:12Z DEBUG 6 2019-01-17T11:03:12Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-conntablesize: 2019-01-17T11:03:12Z DEBUG 16384 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:03:12Z DEBUG month 2019-01-17T11:03:12Z DEBUG nsslapd-saslpath: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG passwordMaxAge: 2019-01-17T11:03:12Z DEBUG 8640000 2019-01-17T11:03:12Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:03:12Z DEBUG gidNumber 2019-01-17T11:03:12Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:03:12Z DEBUG day 2019-01-17T11:03:12Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-csnlogging: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-tmpdir: 2019-01-17T11:03:12Z DEBUG /tmp 2019-01-17T11:03:12Z DEBUG passwordResetFailureCount: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-counters: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-svrtab: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:03:12Z DEBUG month 2019-01-17T11:03:12Z DEBUG nsslapd-minssf: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-schemadir: 2019-01-17T11:03:12Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:03:12Z DEBUG nsslapd-localuser: 2019-01-17T11:03:12Z DEBUG dirsrv 2019-01-17T11:03:12Z DEBUG nsslapd-security: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordChange: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-port 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:03:12Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:03:12Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:03:12Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:03:12Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:03:12Z DEBUG passwordMaxFailure: 2019-01-17T11:03:12Z DEBUG 3 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:03:12Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:03:12Z DEBUG 128 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:03:12Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-rootdn: 2019-01-17T11:03:12Z DEBUG cn=Directory Manager 2019-01-17T11:03:12Z DEBUG nsslapd-ldifdir: 2019-01-17T11:03:12Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:03:12Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG passwordMustChange: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordExp: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG nsslapd-logging-backend: 2019-01-17T11:03:12Z DEBUG dirsrv-log 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:12Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG aci: 2019-01-17T11:03:12Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:03:12Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:03:12Z DEBUG cn=Directory Manager 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordMinLength: 2019-01-17T11:03:12Z DEBUG 8 2019-01-17T11:03:12Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-idletimeout: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:03:12Z DEBUG -10 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:03:12Z DEBUG week 2019-01-17T11:03:12Z DEBUG nsslapd-securePort: 2019-01-17T11:03:12Z DEBUG 636 2019-01-17T11:03:12Z DEBUG nsslapd-snmp-index: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG config 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG extensibleObject 2019-01-17T11:03:12Z DEBUG nsslapdConfig 2019-01-17T11:03:12Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordSendExpiringTime: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-hash-filters: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:03:12Z DEBUG next 2019-01-17T11:03:12Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:03:12Z DEBUG -10 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-listenhost: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordCheckSyntax: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordGraceLimit: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG passwordWarning: 2019-01-17T11:03:12Z DEBUG 86400 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-instancedir: 2019-01-17T11:03:12Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:03:12Z DEBUG nsslapd-config: 2019-01-17T11:03:12Z DEBUG cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-versionstring: 2019-01-17T11:03:12Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:03:12Z DEBUG 256 2019-01-17T11:03:12Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:03:12Z DEBUG 2097152 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:03:12Z DEBUG month 2019-01-17T11:03:12Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:03:12Z DEBUG SSHA512 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG passwordLockout: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-lockdir: 2019-01-17T11:03:12Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:03:12Z DEBUG nsslapd-certdir: 2019-01-17T11:03:12Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:03:12Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:03:12Z DEBUG 10 2019-01-17T11:03:12Z DEBUG nsslapd-backendconfig: 2019-01-17T11:03:12Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-threadnumber: 2019-01-17T11:03:12Z DEBUG 24 2019-01-17T11:03:12Z DEBUG nsslapd-schemamod: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-localhost: 2019-01-17T11:03:12Z DEBUG centos75.local 2019-01-17T11:03:12Z DEBUG nsslapd-bakdir: 2019-01-17T11:03:12Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:03:12Z DEBUG passwordMin8bit: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:03:12Z DEBUG uidNumber 2019-01-17T11:03:12Z DEBUG nsslapd-validate-cert: 2019-01-17T11:03:12Z DEBUG warn 2019-01-17T11:03:12Z DEBUG passwordMinCategories: 2019-01-17T11:03:12Z DEBUG 3 2019-01-17T11:03:12Z DEBUG passwordMinLowers: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordAdminDN: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordMinSpecials: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-lastmod: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:03:12Z DEBUG 40 2019-01-17T11:03:12Z DEBUG passwordMaxRepeats: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:03:12Z DEBUG -1 2019-01-17T11:03:12Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:03:12Z DEBUG none 2019-01-17T11:03:12Z DEBUG nsslapd-result-tweak: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:03:12Z DEBUG month 2019-01-17T11:03:12Z DEBUG passwordUnlock: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-schemacheck: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-maxbersize: 2019-01-17T11:03:12Z DEBUG 209715200 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:03:12Z DEBUG dc=example,dc=com 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-localssf: 2019-01-17T11:03:12Z DEBUG 71 2019-01-17T11:03:12Z DEBUG nsslapd-sizelimit: 2019-01-17T11:03:12Z DEBUG 2000 2019-01-17T11:03:12Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:03:12Z DEBUG dc=local 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:03:12Z DEBUG 2097152 2019-01-17T11:03:12Z DEBUG passwordLockoutDuration: 2019-01-17T11:03:12Z DEBUG 3600 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-port: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:03:12Z DEBUG cn=schema 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG cn=monitor 2019-01-17T11:03:12Z DEBUG cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-rootpw: 2019-01-17T11:03:12Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:03:12Z DEBUG 300000 2019-01-17T11:03:12Z DEBUG nsslapd-workingdir: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-rundir: 2019-01-17T11:03:12Z DEBUG /var/run/dirsrv 2019-01-17T11:03:12Z DEBUG nsslapd-schemareplace: 2019-01-17T11:03:12Z DEBUG replication-only 2019-01-17T11:03:12Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:03:12Z DEBUG 16384 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:03:12Z DEBUG 10000 2019-01-17T11:03:12Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordMinDigits: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG passwordStorageScheme: 2019-01-17T11:03:12Z DEBUG SSHA512 2019-01-17T11:03:12Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG add: '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";)' to aci, current value [u'(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";)', u'(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:12Z DEBUG add: updated value [u'(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-betype: 2019-01-17T11:03:12Z DEBUG ldbm database 2019-01-17T11:03:12Z DEBUG nsslapd-nagle: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-referralmode: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:03:12Z DEBUG 64 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:03:12Z DEBUG 500 2019-01-17T11:03:12Z DEBUG passwordMinAlphas: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-readonly: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordLegacyPolicy: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:03:12Z DEBUG allowed 2019-01-17T11:03:12Z DEBUG passwordMinUppers: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-plugin: 2019-01-17T11:03:12Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:03:12Z DEBUG 2097152 2019-01-17T11:03:12Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:03:12Z DEBUG 20971520 2019-01-17T11:03:12Z DEBUG nsslapd-timelimit: 2019-01-17T11:03:12Z DEBUG 3600 2019-01-17T11:03:12Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordMinTokenLength: 2019-01-17T11:03:12Z DEBUG 3 2019-01-17T11:03:12Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:03:12Z DEBUG -10 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:03:12Z DEBUG week 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG passwordMinAge: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:03:12Z DEBUG week 2019-01-17T11:03:12Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:03:12Z DEBUG 60 2019-01-17T11:03:12Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:03:12Z DEBUG 1024 2019-01-17T11:03:12Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordInHistory: 2019-01-17T11:03:12Z DEBUG 6 2019-01-17T11:03:12Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-conntablesize: 2019-01-17T11:03:12Z DEBUG 16384 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:03:12Z DEBUG month 2019-01-17T11:03:12Z DEBUG nsslapd-saslpath: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG passwordMaxAge: 2019-01-17T11:03:12Z DEBUG 8640000 2019-01-17T11:03:12Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:03:12Z DEBUG gidNumber 2019-01-17T11:03:12Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:03:12Z DEBUG day 2019-01-17T11:03:12Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-csnlogging: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-tmpdir: 2019-01-17T11:03:12Z DEBUG /tmp 2019-01-17T11:03:12Z DEBUG passwordResetFailureCount: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-counters: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-svrtab: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:03:12Z DEBUG month 2019-01-17T11:03:12Z DEBUG nsslapd-minssf: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-schemadir: 2019-01-17T11:03:12Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:03:12Z DEBUG nsslapd-localuser: 2019-01-17T11:03:12Z DEBUG dirsrv 2019-01-17T11:03:12Z DEBUG nsslapd-security: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordChange: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-port 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:03:12Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:03:12Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:03:12Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:03:12Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:03:12Z DEBUG passwordMaxFailure: 2019-01-17T11:03:12Z DEBUG 3 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:03:12Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:03:12Z DEBUG 128 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:03:12Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-rootdn: 2019-01-17T11:03:12Z DEBUG cn=Directory Manager 2019-01-17T11:03:12Z DEBUG nsslapd-ldifdir: 2019-01-17T11:03:12Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:03:12Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG passwordMustChange: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordExp: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG nsslapd-logging-backend: 2019-01-17T11:03:12Z DEBUG dirsrv-log 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:12Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG aci: 2019-01-17T11:03:12Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:03:12Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:03:12Z DEBUG cn=Directory Manager 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordMinLength: 2019-01-17T11:03:12Z DEBUG 8 2019-01-17T11:03:12Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-idletimeout: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:03:12Z DEBUG -10 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:03:12Z DEBUG week 2019-01-17T11:03:12Z DEBUG nsslapd-securePort: 2019-01-17T11:03:12Z DEBUG 636 2019-01-17T11:03:12Z DEBUG nsslapd-snmp-index: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG config 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG extensibleObject 2019-01-17T11:03:12Z DEBUG nsslapdConfig 2019-01-17T11:03:12Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordSendExpiringTime: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-hash-filters: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:03:12Z DEBUG next 2019-01-17T11:03:12Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:03:12Z DEBUG -10 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-listenhost: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordCheckSyntax: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordGraceLimit: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG passwordWarning: 2019-01-17T11:03:12Z DEBUG 86400 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-instancedir: 2019-01-17T11:03:12Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:03:12Z DEBUG nsslapd-config: 2019-01-17T11:03:12Z DEBUG cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-versionstring: 2019-01-17T11:03:12Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:03:12Z DEBUG 256 2019-01-17T11:03:12Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:03:12Z DEBUG 2097152 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:03:12Z DEBUG month 2019-01-17T11:03:12Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:03:12Z DEBUG SSHA512 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG passwordLockout: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-lockdir: 2019-01-17T11:03:12Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:03:12Z DEBUG nsslapd-certdir: 2019-01-17T11:03:12Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:03:12Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:03:12Z DEBUG 10 2019-01-17T11:03:12Z DEBUG nsslapd-backendconfig: 2019-01-17T11:03:12Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-threadnumber: 2019-01-17T11:03:12Z DEBUG 24 2019-01-17T11:03:12Z DEBUG nsslapd-schemamod: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-localhost: 2019-01-17T11:03:12Z DEBUG centos75.local 2019-01-17T11:03:12Z DEBUG nsslapd-bakdir: 2019-01-17T11:03:12Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:03:12Z DEBUG passwordMin8bit: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:03:12Z DEBUG uidNumber 2019-01-17T11:03:12Z DEBUG nsslapd-validate-cert: 2019-01-17T11:03:12Z DEBUG warn 2019-01-17T11:03:12Z DEBUG passwordMinCategories: 2019-01-17T11:03:12Z DEBUG 3 2019-01-17T11:03:12Z DEBUG passwordMinLowers: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordAdminDN: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordMinSpecials: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-lastmod: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:03:12Z DEBUG 40 2019-01-17T11:03:12Z DEBUG passwordMaxRepeats: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:03:12Z DEBUG -1 2019-01-17T11:03:12Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:03:12Z DEBUG none 2019-01-17T11:03:12Z DEBUG nsslapd-result-tweak: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:03:12Z DEBUG month 2019-01-17T11:03:12Z DEBUG passwordUnlock: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-schemacheck: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-maxbersize: 2019-01-17T11:03:12Z DEBUG 209715200 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:03:12Z DEBUG dc=example,dc=com 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-localssf: 2019-01-17T11:03:12Z DEBUG 71 2019-01-17T11:03:12Z DEBUG nsslapd-sizelimit: 2019-01-17T11:03:12Z DEBUG 2000 2019-01-17T11:03:12Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:03:12Z DEBUG dc=local 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:03:12Z DEBUG 2097152 2019-01-17T11:03:12Z DEBUG passwordLockoutDuration: 2019-01-17T11:03:12Z DEBUG 3600 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-port: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:03:12Z DEBUG cn=schema 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG cn=monitor 2019-01-17T11:03:12Z DEBUG cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-rootpw: 2019-01-17T11:03:12Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:03:12Z DEBUG 300000 2019-01-17T11:03:12Z DEBUG nsslapd-workingdir: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-rundir: 2019-01-17T11:03:12Z DEBUG /var/run/dirsrv 2019-01-17T11:03:12Z DEBUG nsslapd-schemareplace: 2019-01-17T11:03:12Z DEBUG replication-only 2019-01-17T11:03:12Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:03:12Z DEBUG 16384 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:03:12Z DEBUG 10000 2019-01-17T11:03:12Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordMinDigits: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG passwordStorageScheme: 2019-01-17T11:03:12Z DEBUG SSHA512 2019-01-17T11:03:12Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG [] 2019-01-17T11:03:12Z DEBUG Updated 0 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG New entry: cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG ipapermission 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG ipapermissiontype: 2019-01-17T11:03:12Z DEBUG SYSTEM 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Add Configuration Sub-Entries 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG ipapermission 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG ipapermissiontype: 2019-01-17T11:03:12Z DEBUG SYSTEM 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Add Configuration Sub-Entries 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=config 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-betype: 2019-01-17T11:03:12Z DEBUG ldbm database 2019-01-17T11:03:12Z DEBUG nsslapd-nagle: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-referralmode: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:03:12Z DEBUG 64 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:03:12Z DEBUG 500 2019-01-17T11:03:12Z DEBUG passwordMinAlphas: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-readonly: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordLegacyPolicy: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:03:12Z DEBUG allowed 2019-01-17T11:03:12Z DEBUG passwordMinUppers: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-plugin: 2019-01-17T11:03:12Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:03:12Z DEBUG 2097152 2019-01-17T11:03:12Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:03:12Z DEBUG 20971520 2019-01-17T11:03:12Z DEBUG nsslapd-timelimit: 2019-01-17T11:03:12Z DEBUG 3600 2019-01-17T11:03:12Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordMinTokenLength: 2019-01-17T11:03:12Z DEBUG 3 2019-01-17T11:03:12Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:03:12Z DEBUG -10 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:03:12Z DEBUG week 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG passwordMinAge: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:03:12Z DEBUG week 2019-01-17T11:03:12Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:03:12Z DEBUG 60 2019-01-17T11:03:12Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:03:12Z DEBUG 1024 2019-01-17T11:03:12Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordInHistory: 2019-01-17T11:03:12Z DEBUG 6 2019-01-17T11:03:12Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-conntablesize: 2019-01-17T11:03:12Z DEBUG 16384 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:03:12Z DEBUG month 2019-01-17T11:03:12Z DEBUG nsslapd-saslpath: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG passwordMaxAge: 2019-01-17T11:03:12Z DEBUG 8640000 2019-01-17T11:03:12Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:03:12Z DEBUG gidNumber 2019-01-17T11:03:12Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:03:12Z DEBUG day 2019-01-17T11:03:12Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-csnlogging: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-tmpdir: 2019-01-17T11:03:12Z DEBUG /tmp 2019-01-17T11:03:12Z DEBUG passwordResetFailureCount: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-counters: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-svrtab: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:03:12Z DEBUG month 2019-01-17T11:03:12Z DEBUG nsslapd-minssf: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-schemadir: 2019-01-17T11:03:12Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:03:12Z DEBUG nsslapd-localuser: 2019-01-17T11:03:12Z DEBUG dirsrv 2019-01-17T11:03:12Z DEBUG nsslapd-security: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordChange: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-port 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:03:12Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:03:12Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:03:12Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:03:12Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:03:12Z DEBUG passwordMaxFailure: 2019-01-17T11:03:12Z DEBUG 3 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:03:12Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:03:12Z DEBUG 128 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:03:12Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-rootdn: 2019-01-17T11:03:12Z DEBUG cn=Directory Manager 2019-01-17T11:03:12Z DEBUG nsslapd-ldifdir: 2019-01-17T11:03:12Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:03:12Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG passwordMustChange: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordExp: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG nsslapd-logging-backend: 2019-01-17T11:03:12Z DEBUG dirsrv-log 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:12Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG aci: 2019-01-17T11:03:12Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:03:12Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:03:12Z DEBUG cn=Directory Manager 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordMinLength: 2019-01-17T11:03:12Z DEBUG 8 2019-01-17T11:03:12Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-idletimeout: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:03:12Z DEBUG -10 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:03:12Z DEBUG week 2019-01-17T11:03:12Z DEBUG nsslapd-securePort: 2019-01-17T11:03:12Z DEBUG 636 2019-01-17T11:03:12Z DEBUG nsslapd-snmp-index: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG config 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG extensibleObject 2019-01-17T11:03:12Z DEBUG nsslapdConfig 2019-01-17T11:03:12Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordSendExpiringTime: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-hash-filters: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:03:12Z DEBUG next 2019-01-17T11:03:12Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:03:12Z DEBUG -10 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-listenhost: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordCheckSyntax: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordGraceLimit: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG passwordWarning: 2019-01-17T11:03:12Z DEBUG 86400 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-instancedir: 2019-01-17T11:03:12Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:03:12Z DEBUG nsslapd-config: 2019-01-17T11:03:12Z DEBUG cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-versionstring: 2019-01-17T11:03:12Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:03:12Z DEBUG 256 2019-01-17T11:03:12Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:03:12Z DEBUG 2097152 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:03:12Z DEBUG month 2019-01-17T11:03:12Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:03:12Z DEBUG SSHA512 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG passwordLockout: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-lockdir: 2019-01-17T11:03:12Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:03:12Z DEBUG nsslapd-certdir: 2019-01-17T11:03:12Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:03:12Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:03:12Z DEBUG 10 2019-01-17T11:03:12Z DEBUG nsslapd-backendconfig: 2019-01-17T11:03:12Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-threadnumber: 2019-01-17T11:03:12Z DEBUG 24 2019-01-17T11:03:12Z DEBUG nsslapd-schemamod: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-localhost: 2019-01-17T11:03:12Z DEBUG centos75.local 2019-01-17T11:03:12Z DEBUG nsslapd-bakdir: 2019-01-17T11:03:12Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:03:12Z DEBUG passwordMin8bit: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:03:12Z DEBUG uidNumber 2019-01-17T11:03:12Z DEBUG nsslapd-validate-cert: 2019-01-17T11:03:12Z DEBUG warn 2019-01-17T11:03:12Z DEBUG passwordMinCategories: 2019-01-17T11:03:12Z DEBUG 3 2019-01-17T11:03:12Z DEBUG passwordMinLowers: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordAdminDN: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordMinSpecials: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-lastmod: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:03:12Z DEBUG 40 2019-01-17T11:03:12Z DEBUG passwordMaxRepeats: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:03:12Z DEBUG -1 2019-01-17T11:03:12Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:03:12Z DEBUG none 2019-01-17T11:03:12Z DEBUG nsslapd-result-tweak: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:03:12Z DEBUG month 2019-01-17T11:03:12Z DEBUG passwordUnlock: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-schemacheck: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-maxbersize: 2019-01-17T11:03:12Z DEBUG 209715200 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:03:12Z DEBUG dc=example,dc=com 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-localssf: 2019-01-17T11:03:12Z DEBUG 71 2019-01-17T11:03:12Z DEBUG nsslapd-sizelimit: 2019-01-17T11:03:12Z DEBUG 2000 2019-01-17T11:03:12Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:03:12Z DEBUG dc=local 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:03:12Z DEBUG 2097152 2019-01-17T11:03:12Z DEBUG passwordLockoutDuration: 2019-01-17T11:03:12Z DEBUG 3600 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-port: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:03:12Z DEBUG cn=schema 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG cn=monitor 2019-01-17T11:03:12Z DEBUG cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-rootpw: 2019-01-17T11:03:12Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:03:12Z DEBUG 300000 2019-01-17T11:03:12Z DEBUG nsslapd-workingdir: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-rundir: 2019-01-17T11:03:12Z DEBUG /var/run/dirsrv 2019-01-17T11:03:12Z DEBUG nsslapd-schemareplace: 2019-01-17T11:03:12Z DEBUG replication-only 2019-01-17T11:03:12Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:03:12Z DEBUG 16384 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:03:12Z DEBUG 10000 2019-01-17T11:03:12Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordMinDigits: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG passwordStorageScheme: 2019-01-17T11:03:12Z DEBUG SSHA512 2019-01-17T11:03:12Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG add: '(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";)' to aci, current value [u'(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";)', u'(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:12Z DEBUG add: updated value [u'(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', u'(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";)', u'(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationsynchour: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-betype: 2019-01-17T11:03:12Z DEBUG ldbm database 2019-01-17T11:03:12Z DEBUG nsslapd-nagle: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-list: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-maxlogsize: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-entryusn-global: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-referralmode: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logminfreediskspace: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-reservedescriptors: 2019-01-17T11:03:12Z DEBUG 64 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2019-01-17T11:03:12Z DEBUG 500 2019-01-17T11:03:12Z DEBUG passwordMinAlphas: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-enquote-sup-oc: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-readonly: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-syntaxcheck: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-unhashed-pw-switch: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordLegacyPolicy: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logbuffering: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-SSLclientAuth: 2019-01-17T11:03:12Z DEBUG allowed 2019-01-17T11:03:12Z DEBUG passwordMinUppers: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-plugin: 2019-01-17T11:03:12Z DEBUG cn=binary syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=country string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=fax syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=guide syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=integer syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=oid syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=integermatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-disk-monitoring-threshold: 2019-01-17T11:03:12Z DEBUG 2097152 2019-01-17T11:03:12Z DEBUG nsslapd-dn-validate-strict: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ndn-cache-max-size: 2019-01-17T11:03:12Z DEBUG 20971520 2019-01-17T11:03:12Z DEBUG nsslapd-timelimit: 2019-01-17T11:03:12Z DEBUG 3600 2019-01-17T11:03:12Z DEBUG nsslapd-disk-monitoring: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordIsGlobalPolicy: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-moddn-aci: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-pwpolicy-inherit-global: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordMinTokenLength: 2019-01-17T11:03:12Z DEBUG 3 2019-01-17T11:03:12Z DEBUG nsslapd-malloc-mxfast: 2019-01-17T11:03:12Z DEBUG -10 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2019-01-17T11:03:12Z DEBUG week 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG passwordMinAge: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2019-01-17T11:03:12Z DEBUG week 2019-01-17T11:03:12Z DEBUG nsslapd-disk-monitoring-grace-period: 2019-01-17T11:03:12Z DEBUG 60 2019-01-17T11:03:12Z DEBUG nsslapd-maxdescriptors: 2019-01-17T11:03:12Z DEBUG 1024 2019-01-17T11:03:12Z DEBUG nsslapd-allow-hashed-passwords: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordInHistory: 2019-01-17T11:03:12Z DEBUG 6 2019-01-17T11:03:12Z DEBUG nsslapd-ssl-check-hostname: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-conntablesize: 2019-01-17T11:03:12Z DEBUG 16384 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logging-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2019-01-17T11:03:12Z DEBUG month 2019-01-17T11:03:12Z DEBUG nsslapd-saslpath: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG passwordMaxAge: 2019-01-17T11:03:12Z DEBUG 8640000 2019-01-17T11:03:12Z DEBUG nsslapd-ldapiautobind: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-extract-pemfiles: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-maxthreadsperconn: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-ldapigidnumbertype: 2019-01-17T11:03:12Z DEBUG gidNumber 2019-01-17T11:03:12Z DEBUG nsslapd-connection-buffer: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2019-01-17T11:03:12Z DEBUG day 2019-01-17T11:03:12Z DEBUG nsslapd-dynamic-plugins: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-csnlogging: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-tmpdir: 2019-01-17T11:03:12Z DEBUG /tmp 2019-01-17T11:03:12Z DEBUG passwordResetFailureCount: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-counters: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-svrtab: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-allowed-sasl-mechanisms: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2019-01-17T11:03:12Z DEBUG month 2019-01-17T11:03:12Z DEBUG nsslapd-minssf: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-maxlogsize: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-schemadir: 2019-01-17T11:03:12Z DEBUG /etc/dirsrv/slapd-LOCAL/schema 2019-01-17T11:03:12Z DEBUG nsslapd-localuser: 2019-01-17T11:03:12Z DEBUG dirsrv 2019-01-17T11:03:12Z DEBUG nsslapd-security: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordChange: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-requiresrestart: 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-port 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-secureport 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-ldapifilepath 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-ldapilisten 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-workingdir 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-plugin 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-sslclientauth 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-changelogdir 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-changelogsuffix 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-changelogmaxentries 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-changelogmaxage 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-db-locks 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-maxdescriptors 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-return-exact-case 2019-01-17T11:03:12Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2019-01-17T11:03:12Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2019-01-17T11:03:12Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2019-01-17T11:03:12Z DEBUG cn=encryption,cn=config:nssslclientauth 2019-01-17T11:03:12Z DEBUG cn=encryption,cn=config:nsssl2 2019-01-17T11:03:12Z DEBUG cn=encryption,cn=config:nsssl3 2019-01-17T11:03:12Z DEBUG passwordMaxFailure: 2019-01-17T11:03:12Z DEBUG 3 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ldapifilepath: 2019-01-17T11:03:12Z DEBUG /var/run/slapd-LOCAL.socket 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logging-enabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-pagedsizelimit: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-global-backend-lock: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logexpirationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-listen-backlog-size: 2019-01-17T11:03:12Z DEBUG 128 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL/access 2019-01-17T11:03:12Z DEBUG nsslapd-certmap-basedn: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-plugin-logging: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-accesscontrol: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-rootdn: 2019-01-17T11:03:12Z DEBUG cn=Directory Manager 2019-01-17T11:03:12Z DEBUG nsslapd-ldifdir: 2019-01-17T11:03:12Z DEBUG /var/lib/dirsrv/slapd-LOCAL/ldif 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-mode: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-anonlimitsdn: 2019-01-17T11:03:12Z DEBUG cn=anonymous-limits,cn=etc,dc=local 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logging-enabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG passwordMustChange: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordExp: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-list: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logminfreediskspace: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG nsslapd-logging-backend: 2019-01-17T11:03:12Z DEBUG dirsrv-log 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:12Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG aci: 2019-01-17T11:03:12Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2019-01-17T11:03:12Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-ldapimaprootdn: 2019-01-17T11:03:12Z DEBUG cn=Directory Manager 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logging-enabled: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ds4-compatible-schema: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-enable-nunc-stans: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordMinLength: 2019-01-17T11:03:12Z DEBUG 8 2019-01-17T11:03:12Z DEBUG nsslapd-require-secure-binds: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-groupevalnestlevel: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-idletimeout: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-malloc-mmap-threshold: 2019-01-17T11:03:12Z DEBUG -10 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2019-01-17T11:03:12Z DEBUG week 2019-01-17T11:03:12Z DEBUG nsslapd-securePort: 2019-01-17T11:03:12Z DEBUG 636 2019-01-17T11:03:12Z DEBUG nsslapd-snmp-index: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG config 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG extensibleObject 2019-01-17T11:03:12Z DEBUG nsslapdConfig 2019-01-17T11:03:12Z DEBUG nsslapd-ldapimaptoentries: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordSendExpiringTime: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-hash-filters: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-entryusn-import-initval: 2019-01-17T11:03:12Z DEBUG next 2019-01-17T11:03:12Z DEBUG nsslapd-malloc-trim-threshold: 2019-01-17T11:03:12Z DEBUG -10 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG nsslapd-ignore-time-skew: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-allow-unauthenticated-binds: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-maxlogsperdir: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-listenhost: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-mode: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL/errors 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-sasl-mapping-fallback: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-disk-monitoring-logging-critical: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-force-sasl-external: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-enable-turbo-mode: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordCheckSyntax: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordGraceLimit: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG passwordWarning: 2019-01-17T11:03:12Z DEBUG 86400 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-mode: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-instancedir: 2019-01-17T11:03:12Z DEBUG /var/lib/dirsrv/scripts-LOCAL 2019-01-17T11:03:12Z DEBUG nsslapd-config: 2019-01-17T11:03:12Z DEBUG cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-versionstring: 2019-01-17T11:03:12Z DEBUG 389-Directory/1.3.8.4 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-level: 2019-01-17T11:03:12Z DEBUG 256 2019-01-17T11:03:12Z DEBUG nsslapd-return-exact-case: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-maxsasliosize: 2019-01-17T11:03:12Z DEBUG 2097152 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2019-01-17T11:03:12Z DEBUG month 2019-01-17T11:03:12Z DEBUG nsslapd-rewrite-rfc1274: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-rootpwstoragescheme: 2019-01-17T11:03:12Z DEBUG SSHA512 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog-logexpirationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG passwordLockout: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-lockdir: 2019-01-17T11:03:12Z DEBUG /var/lock/dirsrv/slapd-LOCAL 2019-01-17T11:03:12Z DEBUG nsslapd-certdir: 2019-01-17T11:03:12Z DEBUG /etc/dirsrv/slapd-LOCAL 2019-01-17T11:03:12Z DEBUG nsslapd-allow-anonymous-access: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-maxlogsperdir: 2019-01-17T11:03:12Z DEBUG 10 2019-01-17T11:03:12Z DEBUG nsslapd-backendconfig: 2019-01-17T11:03:12Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG cn=config,cn=changelog,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-threadnumber: 2019-01-17T11:03:12Z DEBUG 24 2019-01-17T11:03:12Z DEBUG nsslapd-schemamod: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-search-return-original-type-switch: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-localhost: 2019-01-17T11:03:12Z DEBUG centos75.local 2019-01-17T11:03:12Z DEBUG nsslapd-bakdir: 2019-01-17T11:03:12Z DEBUG /var/lib/dirsrv/slapd-LOCAL/bak 2019-01-17T11:03:12Z DEBUG passwordMin8bit: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-ldapiuidnumbertype: 2019-01-17T11:03:12Z DEBUG uidNumber 2019-01-17T11:03:12Z DEBUG nsslapd-validate-cert: 2019-01-17T11:03:12Z DEBUG warn 2019-01-17T11:03:12Z DEBUG passwordMinCategories: 2019-01-17T11:03:12Z DEBUG 3 2019-01-17T11:03:12Z DEBUG passwordMinLowers: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordAdminDN: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-ldapilisten: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordMinSpecials: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-lastmod: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-max-filter-nest-level: 2019-01-17T11:03:12Z DEBUG 40 2019-01-17T11:03:12Z DEBUG passwordMaxRepeats: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-securelistenhost: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-maxsimplepaged-per-conn: 2019-01-17T11:03:12Z DEBUG -1 2019-01-17T11:03:12Z DEBUG nsslapd-tls-check-crl: 2019-01-17T11:03:12Z DEBUG none 2019-01-17T11:03:12Z DEBUG nsslapd-result-tweak: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2019-01-17T11:03:12Z DEBUG month 2019-01-17T11:03:12Z DEBUG passwordUnlock: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-schemacheck: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG passwordTrackUpdateTime: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-maxbersize: 2019-01-17T11:03:12Z DEBUG 209715200 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-maxlogsize: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-ldapientrysearchbase: 2019-01-17T11:03:12Z DEBUG dc=example,dc=com 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logexpirationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-localssf: 2019-01-17T11:03:12Z DEBUG 71 2019-01-17T11:03:12Z DEBUG nsslapd-sizelimit: 2019-01-17T11:03:12Z DEBUG 2000 2019-01-17T11:03:12Z DEBUG nsslapd-minssf-exclude-rootdse: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logrotationsynchour: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-ignore-virtual-attrs: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ndn-cache-enabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationtime: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-defaultnamingcontext: 2019-01-17T11:03:12Z DEBUG dc=local 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-pwpolicy-local: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-sasl-max-buffer-size: 2019-01-17T11:03:12Z DEBUG 2097152 2019-01-17T11:03:12Z DEBUG passwordLockoutDuration: 2019-01-17T11:03:12Z DEBUG 3600 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-list: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-port: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-maxlogsize: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG nsslapd-privatenamespaces: 2019-01-17T11:03:12Z DEBUG cn=schema 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG cn=monitor 2019-01-17T11:03:12Z DEBUG cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-maxlogsperdir: 2019-01-17T11:03:12Z DEBUG 1 2019-01-17T11:03:12Z DEBUG nsslapd-auditlog: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL/audit 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-mode: 2019-01-17T11:03:12Z DEBUG 600 2019-01-17T11:03:12Z DEBUG nsslapd-rootpw: 2019-01-17T11:03:12Z DEBUG {SSHA512}tO8d1iQCtKM6RGlxO8JIeGa6K4fcXVTHHT2PR05D2k0bEY8tJSz+8d6vtHpTrAsSkV+RcAV0UfiAJu6JQ5JxiKCQhq3GaZF7 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-logrotationsynchour: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-outbound-ldap-io-timeout: 2019-01-17T11:03:12Z DEBUG 300000 2019-01-17T11:03:12Z DEBUG nsslapd-workingdir: 2019-01-17T11:03:12Z DEBUG /var/log/dirsrv/slapd-LOCAL 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-list: 2019-01-17T11:03:12Z DEBUG 2019-01-17T11:03:12Z DEBUG nsslapd-rundir: 2019-01-17T11:03:12Z DEBUG /var/run/dirsrv 2019-01-17T11:03:12Z DEBUG nsslapd-schemareplace: 2019-01-17T11:03:12Z DEBUG replication-only 2019-01-17T11:03:12Z DEBUG nsslapd-plugin-binddn-tracking: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-errorlog-level: 2019-01-17T11:03:12Z DEBUG 16384 2019-01-17T11:03:12Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-syntaxlogging: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-ioblocktimeout: 2019-01-17T11:03:12Z DEBUG 10000 2019-01-17T11:03:12Z DEBUG nsslapd-attribute-name-exceptions: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG passwordMinDigits: 2019-01-17T11:03:12Z DEBUG 0 2019-01-17T11:03:12Z DEBUG nsslapd-accesslog-logminfreediskspace: 2019-01-17T11:03:12Z DEBUG 5 2019-01-17T11:03:12Z DEBUG passwordStorageScheme: 2019-01-17T11:03:12Z DEBUG SSHA512 2019-01-17T11:03:12Z DEBUG nsslapd-connection-nocanon: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG [] 2019-01-17T11:03:12Z DEBUG Updated 0 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG New entry: cn=CA Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=CA Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG CA Administrator 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG CA Administrator 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=CA Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG CA Administrator 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG CA Administrator 2019-01-17T11:03:12Z DEBUG New entry: cn=Vault Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=Vault Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Vault Administrators 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Vault Administrators 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=Vault Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Vault Administrators 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Vault Administrators 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=DNS Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=DNS Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG DNS Administrators 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG DNS Administrators 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=DNS Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG DNS Administrators 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG DNS Administrators 2019-01-17T11:03:12Z DEBUG [] 2019-01-17T11:03:12Z DEBUG Updated 0 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=DNS Servers,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=DNS Servers,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG DNS Servers 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG DNS Servers 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=DNS Servers,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG DNS Servers 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG DNS Servers 2019-01-17T11:03:12Z DEBUG [] 2019-01-17T11:03:12Z DEBUG Updated 0 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG Parsing update file '/usr/share/ipa/updates/40-dns.update' 2019-01-17T11:03:12Z DEBUG New entry: cn=dns,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=dns,dc=local 2019-01-17T11:03:12Z DEBUG addifexist: 'idnsConfigObject' to objectClass, current value [] 2019-01-17T11:03:12Z DEBUG addifexist: '(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)' to aci, current value [] 2019-01-17T11:03:12Z DEBUG addifexist: '(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";)' to aci, current value [] 2019-01-17T11:03:12Z DEBUG addifexist: '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' to aci, current value [] 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=dns,dc=local 2019-01-17T11:03:12Z DEBUG New entry: cn=dns,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=dns,dc=local 2019-01-17T11:03:12Z DEBUG replace: (targetattr = "*")(version 3.0; acl "No access to DNS tree without a permission"; deny (read,search,compare) (groupdn != "ldap:///cn=admins,cn=groups,cn=accounts,dc=local") and (groupdn != "ldap:///cn=Read DNS Entries,cn=permissions,cn=pbac,dc=local");) not found, skipping 2019-01-17T11:03:12Z DEBUG replace: (targetattr = "*")(version 3.0; acl "Allow read access"; allow (read,search,compare) groupdn = "ldap:///cn=Read DNS Entries,cn=permissions,cn=pbac,dc=local" or userattr = "parent[0,1].managedby#GROUPDN";) not found, skipping 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=dns,dc=local 2019-01-17T11:03:12Z DEBUG New entry: cn=dns,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=dns,dc=local 2019-01-17T11:03:12Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders")(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' from aci, current value [] 2019-01-17T11:03:12Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders")(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' not in aci 2019-01-17T11:03:12Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders || dlvrecord || idnssecinlinesigning || nsec3paramrecord || tlsarecord ")(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' from aci, current value [] 2019-01-17T11:03:12Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders || dlvrecord || idnssecinlinesigning || nsec3paramrecord || tlsarecord ")(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' not in aci 2019-01-17T11:03:12Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders || dlvrecord || idnssecinlinesigning || nsec3paramrecord || tlsarecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' from aci, current value [] 2019-01-17T11:03:12Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders || dlvrecord || idnssecinlinesigning || nsec3paramrecord || tlsarecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' not in aci 2019-01-17T11:03:12Z DEBUG remove: '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' from aci, current value [] 2019-01-17T11:03:12Z DEBUG remove: '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' not in aci 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=dns,dc=local 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=IPA DNS,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=IPA DNS,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:12Z DEBUG ipa_dns 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG IPA DNS 2019-01-17T11:03:12Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:12Z DEBUG 1.0 2019-01-17T11:03:12Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:12Z DEBUG IPA DNS support plugin 2019-01-17T11:03:12Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:12Z DEBUG libipa_dns.so 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG nsslapdPlugin 2019-01-17T11:03:12Z DEBUG extensibleObject 2019-01-17T11:03:12Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:12Z DEBUG database 2019-01-17T11:03:12Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:12Z DEBUG Red Hat, Inc. 2019-01-17T11:03:12Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:12Z DEBUG preoperation 2019-01-17T11:03:12Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:12Z DEBUG ipadns_init 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=IPA DNS,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:12Z DEBUG ipa_dns 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG IPA DNS 2019-01-17T11:03:12Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:12Z DEBUG 1.0 2019-01-17T11:03:12Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:12Z DEBUG IPA DNS support plugin 2019-01-17T11:03:12Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:12Z DEBUG libipa_dns.so 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG nsslapdPlugin 2019-01-17T11:03:12Z DEBUG extensibleObject 2019-01-17T11:03:12Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:12Z DEBUG database 2019-01-17T11:03:12Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:12Z DEBUG Red Hat, Inc. 2019-01-17T11:03:12Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:12Z DEBUG preoperation 2019-01-17T11:03:12Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:12Z DEBUG ipadns_init 2019-01-17T11:03:12Z DEBUG [] 2019-01-17T11:03:12Z DEBUG Updated 0 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG Parsing update file '/usr/share/ipa/updates/40-otp.update' 2019-01-17T11:03:12Z DEBUG New entry: cn=otp,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=otp,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG nsContainer 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG otp 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=otp,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG nsContainer 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG otp 2019-01-17T11:03:12Z DEBUG New entry: cn=otp,cn=etc,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=otp,cn=etc,dc=local 2019-01-17T11:03:12Z DEBUG ipatokenHOTPsyncWindow: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG ipatokenHOTPauthWindow: 2019-01-17T11:03:12Z DEBUG 10 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG otp 2019-01-17T11:03:12Z DEBUG ipatokenTOTPsyncWindow: 2019-01-17T11:03:12Z DEBUG 86400 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG ipatokenOTPConfig 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG ipatokenTOTPauthWindow: 2019-01-17T11:03:12Z DEBUG 300 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=otp,cn=etc,dc=local 2019-01-17T11:03:12Z DEBUG ipatokenHOTPsyncWindow: 2019-01-17T11:03:12Z DEBUG 100 2019-01-17T11:03:12Z DEBUG ipatokenHOTPauthWindow: 2019-01-17T11:03:12Z DEBUG 10 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG otp 2019-01-17T11:03:12Z DEBUG ipatokenTOTPsyncWindow: 2019-01-17T11:03:12Z DEBUG 86400 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG ipatokenOTPConfig 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG ipatokenTOTPauthWindow: 2019-01-17T11:03:12Z DEBUG 300 2019-01-17T11:03:12Z DEBUG Updating existing entry: dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: dc=local 2019-01-17T11:03:12Z DEBUG info: 2019-01-17T11:03:12Z DEBUG IPA V2.0 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG domain 2019-01-17T11:03:12Z DEBUG pilotObject 2019-01-17T11:03:12Z DEBUG domainRelatedObject 2019-01-17T11:03:12Z DEBUG nisDomainObject 2019-01-17T11:03:12Z DEBUG associatedDomain: 2019-01-17T11:03:12Z DEBUG local 2019-01-17T11:03:12Z DEBUG dc: 2019-01-17T11:03:12Z DEBUG local 2019-01-17T11:03:12Z DEBUG nisDomain: 2019-01-17T11:03:12Z DEBUG local 2019-01-17T11:03:12Z DEBUG aci: 2019-01-17T11:03:12Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2019-01-17T11:03:12Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:12Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:12Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:12Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:12Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:12Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:12Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2019-01-17T11:03:12Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2019-01-17T11:03:12Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2019-01-17T11:03:12Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:12Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:12Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:12Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG remove: '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create and delete tokens"; allow (add, delete) userattr = "ipatokenOwner#SELFDN";)' from aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:12Z DEBUG remove: '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create and delete tokens"; allow (add, delete) userattr = "ipatokenOwner#SELFDN";)' not in aci 2019-01-17T11:03:12Z DEBUG remove: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || ipatokenUniqueID || description || ipatokenOwner || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Users can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN";)' from aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:12Z DEBUG remove: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || ipatokenUniqueID || description || ipatokenOwner || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Users can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN";)' not in aci 2019-01-17T11:03:12Z DEBUG remove: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "ipatokenUniqueID || description || ipatokenOwner || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Users can write basic token info"; allow (write) userattr = "ipatokenOwner#USERDN";)' from aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:12Z DEBUG remove: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "ipatokenUniqueID || description || ipatokenOwner || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Users can write basic token info"; allow (write) userattr = "ipatokenOwner#USERDN";)' not in aci 2019-01-17T11:03:12Z DEBUG remove: '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPkey || ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPclockOffset || ipatokenTOTPtimeStep")(version 3.0; acl "Users can add TOTP token secrets"; allow (write, search) userattr = "ipatokenOwner#USERDN";)' from aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:12Z DEBUG remove: '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPkey || ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPclockOffset || ipatokenTOTPtimeStep")(version 3.0; acl "Users can add TOTP token secrets"; allow (write, search) userattr = "ipatokenOwner#USERDN";)' not in aci 2019-01-17T11:03:12Z DEBUG remove: '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPkey || ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenHOTPcounter")(version 3.0; acl "Users can add HOTP token secrets"; allow (write, search) userattr = "ipatokenOwner#USERDN";)' from aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:12Z DEBUG remove: '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPkey || ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenHOTPcounter")(version 3.0; acl "Users can add HOTP token secrets"; allow (write, search) userattr = "ipatokenOwner#USERDN";)' not in aci 2019-01-17T11:03:12Z DEBUG add: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:12Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2019-01-17T11:03:12Z DEBUG add: '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2019-01-17T11:03:12Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2019-01-17T11:03:12Z DEBUG add: '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2019-01-17T11:03:12Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2019-01-17T11:03:12Z DEBUG add: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2019-01-17T11:03:12Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)'] 2019-01-17T11:03:12Z DEBUG add: '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)'] 2019-01-17T11:03:12Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)'] 2019-01-17T11:03:12Z DEBUG add: '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)'] 2019-01-17T11:03:12Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)'] 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: dc=local 2019-01-17T11:03:12Z DEBUG info: 2019-01-17T11:03:12Z DEBUG IPA V2.0 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG domain 2019-01-17T11:03:12Z DEBUG pilotObject 2019-01-17T11:03:12Z DEBUG domainRelatedObject 2019-01-17T11:03:12Z DEBUG nisDomainObject 2019-01-17T11:03:12Z DEBUG associatedDomain: 2019-01-17T11:03:12Z DEBUG local 2019-01-17T11:03:12Z DEBUG dc: 2019-01-17T11:03:12Z DEBUG local 2019-01-17T11:03:12Z DEBUG nisDomain: 2019-01-17T11:03:12Z DEBUG local 2019-01-17T11:03:12Z DEBUG aci: 2019-01-17T11:03:12Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2019-01-17T11:03:12Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:12Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:12Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:12Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:12Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:12Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:12Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:12Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:12Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:12Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2019-01-17T11:03:12Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2019-01-17T11:03:12Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2019-01-17T11:03:12Z DEBUG [] 2019-01-17T11:03:12Z DEBUG Updated 0 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG New entry: cn=radiusproxy,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=radiusproxy,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG nsContainer 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG radiusproxy 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=radiusproxy,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG nsContainer 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG radiusproxy 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=IPA OTP Last Token,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=IPA OTP Last Token,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:12Z DEBUG ipa-otp-lasttoken 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG IPA OTP Last Token 2019-01-17T11:03:12Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:12Z DEBUG FreeIPA/1.0 2019-01-17T11:03:12Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:12Z DEBUG Protect the user's last active token 2019-01-17T11:03:12Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:12Z DEBUG libipa_otp_lasttoken 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG nsSlapdPlugin 2019-01-17T11:03:12Z DEBUG extensibleObject 2019-01-17T11:03:12Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:12Z DEBUG database 2019-01-17T11:03:12Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:12Z DEBUG FreeIPA 2019-01-17T11:03:12Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:12Z DEBUG preoperation 2019-01-17T11:03:12Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:12Z DEBUG ipa_otp_lasttoken_init 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=IPA OTP Last Token,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:12Z DEBUG ipa-otp-lasttoken 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG IPA OTP Last Token 2019-01-17T11:03:12Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:12Z DEBUG FreeIPA/1.0 2019-01-17T11:03:12Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:12Z DEBUG Protect the user's last active token 2019-01-17T11:03:12Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:12Z DEBUG libipa_otp_lasttoken 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG nsSlapdPlugin 2019-01-17T11:03:12Z DEBUG extensibleObject 2019-01-17T11:03:12Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:12Z DEBUG database 2019-01-17T11:03:12Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:12Z DEBUG FreeIPA 2019-01-17T11:03:12Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:12Z DEBUG preoperation 2019-01-17T11:03:12Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:12Z DEBUG ipa_otp_lasttoken_init 2019-01-17T11:03:12Z DEBUG [] 2019-01-17T11:03:12Z DEBUG Updated 0 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=IPA OTP Counter,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=IPA OTP Counter,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:12Z DEBUG ipa-otp-counter 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG IPA OTP Counter 2019-01-17T11:03:12Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:12Z DEBUG FreeIPA/1.0 2019-01-17T11:03:12Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:12Z DEBUG Ensure proper OTP token counter operation 2019-01-17T11:03:12Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:12Z DEBUG libipa_otp_counter 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG nsSlapdPlugin 2019-01-17T11:03:12Z DEBUG extensibleObject 2019-01-17T11:03:12Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:12Z DEBUG database 2019-01-17T11:03:12Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:12Z DEBUG FreeIPA 2019-01-17T11:03:12Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:12Z DEBUG preoperation 2019-01-17T11:03:12Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:12Z DEBUG ipa_otp_counter_init 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=IPA OTP Counter,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:12Z DEBUG ipa-otp-counter 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG IPA OTP Counter 2019-01-17T11:03:12Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:12Z DEBUG FreeIPA/1.0 2019-01-17T11:03:12Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:12Z DEBUG Ensure proper OTP token counter operation 2019-01-17T11:03:12Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:12Z DEBUG libipa_otp_counter 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG nsSlapdPlugin 2019-01-17T11:03:12Z DEBUG extensibleObject 2019-01-17T11:03:12Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:12Z DEBUG database 2019-01-17T11:03:12Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:12Z DEBUG FreeIPA 2019-01-17T11:03:12Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:12Z DEBUG preoperation 2019-01-17T11:03:12Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:12Z DEBUG ipa_otp_counter_init 2019-01-17T11:03:12Z DEBUG [] 2019-01-17T11:03:12Z DEBUG Updated 0 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG Parsing update file '/usr/share/ipa/updates/40-realm_domains.update' 2019-01-17T11:03:12Z DEBUG New entry: cn=Realm Domains,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=Realm Domains,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG domainRelatedObject 2019-01-17T11:03:12Z DEBUG nsContainer 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG associatedDomain: 2019-01-17T11:03:12Z DEBUG local 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Realm Domains 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=Realm Domains,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG domainRelatedObject 2019-01-17T11:03:12Z DEBUG nsContainer 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG associatedDomain: 2019-01-17T11:03:12Z DEBUG local 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Realm Domains 2019-01-17T11:03:12Z DEBUG Parsing update file '/usr/share/ipa/updates/40-replication.update' 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-directory: 2019-01-17T11:03:12Z DEBUG /var/lib/dirsrv/slapd-LOCAL/db/userRoot 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG userRoot 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG extensibleObject 2019-01-17T11:03:12Z DEBUG nsBackendInstance 2019-01-17T11:03:12Z DEBUG nsslapd-require-index: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG aci: 2019-01-17T11:03:12Z DEBUG (targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG nsslapd-suffix: 2019-01-17T11:03:12Z DEBUG dc=local 2019-01-17T11:03:12Z DEBUG nsslapd-readonly: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-dncachememsize: 2019-01-17T11:03:12Z DEBUG 67108864 2019-01-17T11:03:12Z DEBUG nsslapd-cachesize: 2019-01-17T11:03:12Z DEBUG -1 2019-01-17T11:03:12Z DEBUG nsslapd-cachememsize: 2019-01-17T11:03:12Z DEBUG 67108864 2019-01-17T11:03:12Z DEBUG add: '(targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";)' to aci, current value [u'(targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:12Z DEBUG add: updated value [u'(targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-directory: 2019-01-17T11:03:12Z DEBUG /var/lib/dirsrv/slapd-LOCAL/db/userRoot 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG userRoot 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG extensibleObject 2019-01-17T11:03:12Z DEBUG nsBackendInstance 2019-01-17T11:03:12Z DEBUG nsslapd-require-index: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG aci: 2019-01-17T11:03:12Z DEBUG (targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG nsslapd-suffix: 2019-01-17T11:03:12Z DEBUG dc=local 2019-01-17T11:03:12Z DEBUG nsslapd-readonly: 2019-01-17T11:03:12Z DEBUG off 2019-01-17T11:03:12Z DEBUG nsslapd-dncachememsize: 2019-01-17T11:03:12Z DEBUG 67108864 2019-01-17T11:03:12Z DEBUG nsslapd-cachesize: 2019-01-17T11:03:12Z DEBUG -1 2019-01-17T11:03:12Z DEBUG nsslapd-cachememsize: 2019-01-17T11:03:12Z DEBUG 67108864 2019-01-17T11:03:12Z DEBUG [] 2019-01-17T11:03:12Z DEBUG Updated 0 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=Modify DNA Range,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=Modify DNA Range,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG ipapermission 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG ipaPermissionType: 2019-01-17T11:03:12Z DEBUG SYSTEM 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Modify DNA Range 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=Modify DNA Range,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG ipapermission 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG ipaPermissionType: 2019-01-17T11:03:12Z DEBUG SYSTEM 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Modify DNA Range 2019-01-17T11:03:12Z DEBUG [] 2019-01-17T11:03:12Z DEBUG Updated 0 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG dnaScope: 2019-01-17T11:03:12Z DEBUG dc=local 2019-01-17T11:03:12Z DEBUG dnaThreshold: 2019-01-17T11:03:12Z DEBUG 500 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Posix IDs 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG extensibleObject 2019-01-17T11:03:12Z DEBUG aci: 2019-01-17T11:03:12Z DEBUG (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG dnaMagicRegen: 2019-01-17T11:03:12Z DEBUG -1 2019-01-17T11:03:12Z DEBUG dnaNextValue: 2019-01-17T11:03:12Z DEBUG 353600000 2019-01-17T11:03:12Z DEBUG dnaExcludeScope: 2019-01-17T11:03:12Z DEBUG cn=provisioning,dc=local 2019-01-17T11:03:12Z DEBUG dnaFilter: 2019-01-17T11:03:12Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2019-01-17T11:03:12Z DEBUG dnaType: 2019-01-17T11:03:12Z DEBUG uidNumber 2019-01-17T11:03:12Z DEBUG gidNumber 2019-01-17T11:03:12Z DEBUG dnaMaxValue: 2019-01-17T11:03:12Z DEBUG 353799999 2019-01-17T11:03:12Z DEBUG dnaSharedCfgDN: 2019-01-17T11:03:12Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:12Z DEBUG add: '(targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=local";)' to aci, current value [u'(targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:12Z DEBUG add: updated value [u'(targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG dnaScope: 2019-01-17T11:03:12Z DEBUG dc=local 2019-01-17T11:03:12Z DEBUG dnaThreshold: 2019-01-17T11:03:12Z DEBUG 500 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Posix IDs 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG extensibleObject 2019-01-17T11:03:12Z DEBUG aci: 2019-01-17T11:03:12Z DEBUG (targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG dnaMagicRegen: 2019-01-17T11:03:12Z DEBUG -1 2019-01-17T11:03:12Z DEBUG dnaNextValue: 2019-01-17T11:03:12Z DEBUG 353600000 2019-01-17T11:03:12Z DEBUG dnaExcludeScope: 2019-01-17T11:03:12Z DEBUG cn=provisioning,dc=local 2019-01-17T11:03:12Z DEBUG dnaFilter: 2019-01-17T11:03:12Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2019-01-17T11:03:12Z DEBUG dnaType: 2019-01-17T11:03:12Z DEBUG uidNumber 2019-01-17T11:03:12Z DEBUG gidNumber 2019-01-17T11:03:12Z DEBUG dnaMaxValue: 2019-01-17T11:03:12Z DEBUG 353799999 2019-01-17T11:03:12Z DEBUG dnaSharedCfgDN: 2019-01-17T11:03:12Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:12Z DEBUG [] 2019-01-17T11:03:12Z DEBUG Updated 0 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG New entry: cn=Read DNA Range,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=Read DNA Range,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG ipapermission 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG ipapermissiontype: 2019-01-17T11:03:12Z DEBUG SYSTEM 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Read DNA Range 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=Read DNA Range,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG ipapermission 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG ipapermissiontype: 2019-01-17T11:03:12Z DEBUG SYSTEM 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Read DNA Range 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG dnaScope: 2019-01-17T11:03:12Z DEBUG dc=local 2019-01-17T11:03:12Z DEBUG dnaThreshold: 2019-01-17T11:03:12Z DEBUG 500 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Posix IDs 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG extensibleObject 2019-01-17T11:03:12Z DEBUG aci: 2019-01-17T11:03:12Z DEBUG (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG dnaMagicRegen: 2019-01-17T11:03:12Z DEBUG -1 2019-01-17T11:03:12Z DEBUG dnaNextValue: 2019-01-17T11:03:12Z DEBUG 353600000 2019-01-17T11:03:12Z DEBUG dnaExcludeScope: 2019-01-17T11:03:12Z DEBUG cn=provisioning,dc=local 2019-01-17T11:03:12Z DEBUG dnaFilter: 2019-01-17T11:03:12Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2019-01-17T11:03:12Z DEBUG dnaType: 2019-01-17T11:03:12Z DEBUG uidNumber 2019-01-17T11:03:12Z DEBUG gidNumber 2019-01-17T11:03:12Z DEBUG dnaMaxValue: 2019-01-17T11:03:12Z DEBUG 353799999 2019-01-17T11:03:12Z DEBUG dnaSharedCfgDN: 2019-01-17T11:03:12Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:12Z DEBUG add: '(targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=local";)' to aci, current value [u'(targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:12Z DEBUG add: updated value [u'(targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=local";)', u'(targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG dnaScope: 2019-01-17T11:03:12Z DEBUG dc=local 2019-01-17T11:03:12Z DEBUG dnaThreshold: 2019-01-17T11:03:12Z DEBUG 500 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Posix IDs 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG extensibleObject 2019-01-17T11:03:12Z DEBUG aci: 2019-01-17T11:03:12Z DEBUG (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG dnaMagicRegen: 2019-01-17T11:03:12Z DEBUG -1 2019-01-17T11:03:12Z DEBUG dnaNextValue: 2019-01-17T11:03:12Z DEBUG 353600000 2019-01-17T11:03:12Z DEBUG dnaExcludeScope: 2019-01-17T11:03:12Z DEBUG cn=provisioning,dc=local 2019-01-17T11:03:12Z DEBUG dnaFilter: 2019-01-17T11:03:12Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2019-01-17T11:03:12Z DEBUG dnaType: 2019-01-17T11:03:12Z DEBUG uidNumber 2019-01-17T11:03:12Z DEBUG gidNumber 2019-01-17T11:03:12Z DEBUG dnaMaxValue: 2019-01-17T11:03:12Z DEBUG 353799999 2019-01-17T11:03:12Z DEBUG dnaSharedCfgDN: 2019-01-17T11:03:12Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:12Z DEBUG [] 2019-01-17T11:03:12Z DEBUG Updated 0 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG Parsing update file '/usr/share/ipa/updates/40-vault.update' 2019-01-17T11:03:12Z DEBUG New entry: cn=vaults,cn=kra,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=vaults,cn=kra,dc=local 2019-01-17T11:03:12Z DEBUG remove: '(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=local")(version 3.0; acl "Allow users to create private container"; allow (add) userdn = "ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=local";)' from aci, current value [] 2019-01-17T11:03:12Z DEBUG remove: '(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=local")(version 3.0; acl "Allow users to create private container"; allow (add) userdn = "ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=local";)' not in aci 2019-01-17T11:03:12Z DEBUG remove: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=local")(version 3.0; acl "Allow services to create private container"; allow (add) userdn = "ldap:///krbprincipalname=($attr.cn)@LOCAL,cn=services,cn=accounts,dc=local";)' from aci, current value [] 2019-01-17T11:03:12Z DEBUG remove: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=local")(version 3.0; acl "Allow services to create private container"; allow (add) userdn = "ldap:///krbprincipalname=($attr.cn)@LOCAL,cn=services,cn=accounts,dc=local";)' not in aci 2019-01-17T11:03:12Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Container owners can manage vaults in the container"; allow(read, search, compare, add, delete) userattr="parent[1].owner#USERDN";)' from aci, current value [] 2019-01-17T11:03:12Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Container owners can manage vaults in the container"; allow(read, search, compare, add, delete) userattr="parent[1].owner#USERDN";)' not in aci 2019-01-17T11:03:12Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect container owners can manage vaults in the container"; allow(read, search, compare, add, delete) userattr="parent[1].owner#GROUPDN";)' from aci, current value [] 2019-01-17T11:03:12Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect container owners can manage vaults in the container"; allow(read, search, compare, add, delete) userattr="parent[1].owner#GROUPDN";)' not in aci 2019-01-17T11:03:12Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Vault members can access the vault"; allow(read, search, compare) userattr="member#USERDN";)' from aci, current value [] 2019-01-17T11:03:12Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Vault members can access the vault"; allow(read, search, compare) userattr="member#USERDN";)' not in aci 2019-01-17T11:03:12Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect vault members can access the vault"; allow(read, search, compare) userattr="member#GROUPDN";)' from aci, current value [] 2019-01-17T11:03:12Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect vault members can access the vault"; allow(read, search, compare) userattr="member#GROUPDN";)' not in aci 2019-01-17T11:03:12Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Vault owners can manage the vault"; allow(read, search, compare, write) userattr="owner#USERDN";)' from aci, current value [] 2019-01-17T11:03:12Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Vault owners can manage the vault"; allow(read, search, compare, write) userattr="owner#USERDN";)' not in aci 2019-01-17T11:03:12Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect vault owners can manage the vault"; allow(read, search, compare, write) userattr="owner#GROUPDN";)' from aci, current value [] 2019-01-17T11:03:12Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect vault owners can manage the vault"; allow(read, search, compare, write) userattr="owner#GROUPDN";)' not in aci 2019-01-17T11:03:12Z DEBUG remove: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=local")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn)@LOCAL,cn=services,cn=accounts,dc=local" and userattr="owner#SELFDN";)' from aci, current value [] 2019-01-17T11:03:12Z DEBUG remove: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=local")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn)@LOCAL,cn=services,cn=accounts,dc=local" and userattr="owner#SELFDN";)' not in aci 2019-01-17T11:03:12Z DEBUG addifexist: '(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=local")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=local" and userattr="owner#SELFDN";)' to aci, current value [] 2019-01-17T11:03:12Z DEBUG addifexist: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=local")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn),cn=services,cn=accounts,dc=local" and userattr="owner#SELFDN";)' to aci, current value [] 2019-01-17T11:03:12Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Container owners can access the container"; allow(read, search, compare) userattr="owner#USERDN";)' to aci, current value [] 2019-01-17T11:03:12Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Indirect container owners can access the container"; allow(read, search, compare) userattr="owner#GROUPDN";)' to aci, current value [] 2019-01-17T11:03:12Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Container owners can manage the container"; allow(write, delete) userattr="owner#USERDN";)' to aci, current value [] 2019-01-17T11:03:12Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Indirect container owners can manage the container"; allow(write, delete) userattr="owner#GROUPDN";)' to aci, current value [] 2019-01-17T11:03:12Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#USERDN" and userattr="owner#SELFDN";)' to aci, current value [] 2019-01-17T11:03:12Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Indirect container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#GROUPDN" and userattr="owner#SELFDN";)' to aci, current value [] 2019-01-17T11:03:12Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault owners can access the vault"; allow(read, search, compare) userattr="owner#USERDN";)' to aci, current value [] 2019-01-17T11:03:12Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Indirect vault owners can access the vault"; allow(read, search, compare) userattr="owner#GROUPDN";)' to aci, current value [] 2019-01-17T11:03:12Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault members can access the vault"; allow(read, search, compare) userattr="member#USERDN";)' to aci, current value [] 2019-01-17T11:03:12Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Indirect vault members can access the vault"; allow(read, search, compare) userattr="member#GROUPDN";)' to aci, current value [] 2019-01-17T11:03:12Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || member")(version 3.0; acl "Vault owners can manage the vault"; allow(write, delete) userattr="owner#USERDN";)' to aci, current value [] 2019-01-17T11:03:12Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || member")(version 3.0; acl "Indirect vault owners can manage the vault"; allow(write, delete) userattr="owner#GROUPDN";)' to aci, current value [] 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=vaults,cn=kra,dc=local 2019-01-17T11:03:12Z DEBUG Parsing update file '/usr/share/ipa/updates/41-caacl.update' 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=caacls,cn=ca,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=caacls,cn=ca,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG nsContainer 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG aci: 2019-01-17T11:03:12Z DEBUG (targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Add CA ACL";allow (add) groupdn = "ldap:///cn=System: Add CA ACL,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Delete CA ACL";allow (delete) groupdn = "ldap:///cn=System: Delete CA ACL,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "hostcategory || ipacacategory || ipacertprofilecategory || ipamemberca || ipamembercertprofile || memberhost || memberservice || memberuser || servicecategory || usercategory")(targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Manage CA ACL Membership";allow (write) groupdn = "ldap:///cn=System: Manage CA ACL Membership,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "cn || description || ipaenabledflag")(targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Modify CA ACL";allow (write) groupdn = "ldap:///cn=System: Modify CA ACL,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || hostcategory || ipacacategory || ipacertprofilecategory || ipaenabledflag || ipamemberca || ipamembercertprofile || ipauniqueid || member || memberhost || memberservice || memberuser || modifytimestamp || objectclass || servicecategory || usercategory")(targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Read CA ACLs";allow (compare,read,search) userdn = "ldap:///all";) 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG caacls 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=caacls,cn=ca,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG nsContainer 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG aci: 2019-01-17T11:03:12Z DEBUG (targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Add CA ACL";allow (add) groupdn = "ldap:///cn=System: Add CA ACL,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Delete CA ACL";allow (delete) groupdn = "ldap:///cn=System: Delete CA ACL,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "hostcategory || ipacacategory || ipacertprofilecategory || ipamemberca || ipamembercertprofile || memberhost || memberservice || memberuser || servicecategory || usercategory")(targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Manage CA ACL Membership";allow (write) groupdn = "ldap:///cn=System: Manage CA ACL Membership,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "cn || description || ipaenabledflag")(targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Modify CA ACL";allow (write) groupdn = "ldap:///cn=System: Modify CA ACL,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || hostcategory || ipacacategory || ipacertprofilecategory || ipaenabledflag || ipamemberca || ipamembercertprofile || ipauniqueid || member || memberhost || memberservice || memberuser || modifytimestamp || objectclass || servicecategory || usercategory")(targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Read CA ACLs";allow (compare,read,search) userdn = "ldap:///all";) 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG caacls 2019-01-17T11:03:12Z DEBUG [] 2019-01-17T11:03:12Z DEBUG Updated 0 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG Parsing update file '/usr/share/ipa/updates/41-lightweight-cas.update' 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=cas,cn=ca,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=cas,cn=ca,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG nsContainer 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG aci: 2019-01-17T11:03:12Z DEBUG (targetfilter = "(objectclass=ipaca)")(version 3.0;acl "permission:System: Add CA";allow (add) groupdn = "ldap:///cn=System: Add CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetfilter = "(objectclass=ipaca)")(version 3.0;acl "permission:System: Delete CA";allow (delete) groupdn = "ldap:///cn=System: Delete CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "cn || description")(targetfilter = "(objectclass=ipaca)")(version 3.0;acl "permission:System: Modify CA";allow (write) groupdn = "ldap:///cn=System: Modify CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipacaid || ipacaissuerdn || ipacasubjectdn || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaca)")(version 3.0;acl "permission:System: Read CAs";allow (compare,read,search) userdn = "ldap:///all";) 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG cas 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=cas,cn=ca,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG nsContainer 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG aci: 2019-01-17T11:03:12Z DEBUG (targetfilter = "(objectclass=ipaca)")(version 3.0;acl "permission:System: Add CA";allow (add) groupdn = "ldap:///cn=System: Add CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetfilter = "(objectclass=ipaca)")(version 3.0;acl "permission:System: Delete CA";allow (delete) groupdn = "ldap:///cn=System: Delete CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "cn || description")(targetfilter = "(objectclass=ipaca)")(version 3.0;acl "permission:System: Modify CA";allow (write) groupdn = "ldap:///cn=System: Modify CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:12Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipacaid || ipacaissuerdn || ipacasubjectdn || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaca)")(version 3.0;acl "permission:System: Read CAs";allow (compare,read,search) userdn = "ldap:///all";) 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG cas 2019-01-17T11:03:12Z DEBUG [] 2019-01-17T11:03:12Z DEBUG Updated 0 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG Parsing update file '/usr/share/ipa/updates/45-roles.update' 2019-01-17T11:03:12Z DEBUG New entry: cn=Modify Users and Reset passwords,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=Modify Users and Reset passwords,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG cn=helpdesk,cn=roles,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Modify Users and Reset passwords 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Modify Users and Reset passwords 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=Modify Users and Reset passwords,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG cn=helpdesk,cn=roles,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Modify Users and Reset passwords 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Modify Users and Reset passwords 2019-01-17T11:03:12Z DEBUG New entry: cn=Modify Group membership,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=Modify Group membership,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG cn=helpdesk,cn=roles,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Modify Group membership 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Modify Group membership 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=Modify Group membership,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG cn=helpdesk,cn=roles,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Modify Group membership 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Modify Group membership 2019-01-17T11:03:12Z DEBUG New entry: cn=User Administrator,cn=roles,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=User Administrator,cn=roles,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG User Administrator 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Responsible for creating Users and Groups 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=User Administrator,cn=roles,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG User Administrator 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Responsible for creating Users and Groups 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=User Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=User Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG User Administrators 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG User Administrators 2019-01-17T11:03:12Z DEBUG add: 'cn=User Administrator,cn=roles,cn=accounts,dc=local' to member, current value [] 2019-01-17T11:03:12Z DEBUG add: updated value [u'cn=User Administrator,cn=roles,cn=accounts,dc=local'] 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=User Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG cn=User Administrator,cn=roles,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG User Administrators 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG User Administrators 2019-01-17T11:03:12Z DEBUG [(2, u'member', [u'cn=User Administrator,cn=roles,cn=accounts,dc=local'])] 2019-01-17T11:03:12Z DEBUG Updated 1 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=Group Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=Group Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Group Administrators 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Group Administrators 2019-01-17T11:03:12Z DEBUG add: 'cn=User Administrator,cn=roles,cn=accounts,dc=local' to member, current value [] 2019-01-17T11:03:12Z DEBUG add: updated value [u'cn=User Administrator,cn=roles,cn=accounts,dc=local'] 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=Group Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG cn=User Administrator,cn=roles,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Group Administrators 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Group Administrators 2019-01-17T11:03:12Z DEBUG [(2, u'member', [u'cn=User Administrator,cn=roles,cn=accounts,dc=local'])] 2019-01-17T11:03:12Z DEBUG Updated 1 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=Stage User Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=Stage User Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Stage User Administrators 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Stage User Administrators 2019-01-17T11:03:12Z DEBUG add: 'cn=User Administrator,cn=roles,cn=accounts,dc=local' to member, current value [] 2019-01-17T11:03:12Z DEBUG add: updated value [u'cn=User Administrator,cn=roles,cn=accounts,dc=local'] 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=Stage User Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG cn=User Administrator,cn=roles,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Stage User Administrators 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Stage User Administrators 2019-01-17T11:03:12Z DEBUG [(2, u'member', [u'cn=User Administrator,cn=roles,cn=accounts,dc=local'])] 2019-01-17T11:03:12Z DEBUG Updated 1 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG New entry: cn=IT Specialist,cn=roles,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=IT Specialist,cn=roles,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG IT Specialist 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG IT Specialist 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=IT Specialist,cn=roles,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG IT Specialist 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG IT Specialist 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=Host Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=Host Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG memberOf: 2019-01-17T11:03:12Z DEBUG cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Host Administrators 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Host Administrators 2019-01-17T11:03:12Z DEBUG add: 'cn=IT Specialist,cn=roles,cn=accounts,dc=local' to member, current value [] 2019-01-17T11:03:12Z DEBUG add: updated value [u'cn=IT Specialist,cn=roles,cn=accounts,dc=local'] 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=Host Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG memberOf: 2019-01-17T11:03:12Z DEBUG cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG cn=IT Specialist,cn=roles,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Host Administrators 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Host Administrators 2019-01-17T11:03:12Z DEBUG [(2, u'member', [u'cn=IT Specialist,cn=roles,cn=accounts,dc=local'])] 2019-01-17T11:03:12Z DEBUG Updated 1 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=Host Group Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=Host Group Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Host Group Administrators 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Host Group Administrators 2019-01-17T11:03:12Z DEBUG add: 'cn=IT Specialist,cn=roles,cn=accounts,dc=local' to member, current value [] 2019-01-17T11:03:12Z DEBUG add: updated value [u'cn=IT Specialist,cn=roles,cn=accounts,dc=local'] 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=Host Group Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG cn=IT Specialist,cn=roles,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Host Group Administrators 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Host Group Administrators 2019-01-17T11:03:12Z DEBUG [(2, u'member', [u'cn=IT Specialist,cn=roles,cn=accounts,dc=local'])] 2019-01-17T11:03:12Z DEBUG Updated 1 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=Service Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=Service Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Service Administrators 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Service Administrators 2019-01-17T11:03:12Z DEBUG add: 'cn=IT Specialist,cn=roles,cn=accounts,dc=local' to member, current value [] 2019-01-17T11:03:12Z DEBUG add: updated value [u'cn=IT Specialist,cn=roles,cn=accounts,dc=local'] 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=Service Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG cn=IT Specialist,cn=roles,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Service Administrators 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Service Administrators 2019-01-17T11:03:12Z DEBUG [(2, u'member', [u'cn=IT Specialist,cn=roles,cn=accounts,dc=local'])] 2019-01-17T11:03:12Z DEBUG Updated 1 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=Automount Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=Automount Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG memberOf: 2019-01-17T11:03:12Z DEBUG cn=System: Add Automount Keys,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=System: Modify Automount Keys,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=System: Remove Automount Keys,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=System: Add Automount Locations,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=System: Remove Automount Locations,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=System: Add Automount Maps,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=System: Modify Automount Maps,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=System: Remove Automount Maps,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Automount Administrators 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Automount Administrators 2019-01-17T11:03:12Z DEBUG add: 'cn=IT Specialist,cn=roles,cn=accounts,dc=local' to member, current value [] 2019-01-17T11:03:12Z DEBUG add: updated value [u'cn=IT Specialist,cn=roles,cn=accounts,dc=local'] 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=Automount Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG memberOf: 2019-01-17T11:03:12Z DEBUG cn=System: Add Automount Keys,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=System: Modify Automount Keys,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=System: Remove Automount Keys,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=System: Add Automount Locations,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=System: Remove Automount Locations,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=System: Add Automount Maps,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=System: Modify Automount Maps,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=System: Remove Automount Maps,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG cn=IT Specialist,cn=roles,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Automount Administrators 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Automount Administrators 2019-01-17T11:03:12Z DEBUG [(2, u'member', [u'cn=IT Specialist,cn=roles,cn=accounts,dc=local'])] 2019-01-17T11:03:12Z DEBUG Updated 1 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG New entry: cn=IT Security Specialist,cn=roles,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=IT Security Specialist,cn=roles,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG IT Security Specialist 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG IT Security Specialist 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=IT Security Specialist,cn=roles,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG IT Security Specialist 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG IT Security Specialist 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=Netgroups Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=Netgroups Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Netgroups Administrators 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Netgroups Administrators 2019-01-17T11:03:12Z DEBUG add: 'cn=IT Security Specialist,cn=roles,cn=accounts,dc=local' to member, current value [] 2019-01-17T11:03:12Z DEBUG add: updated value [u'cn=IT Security Specialist,cn=roles,cn=accounts,dc=local'] 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=Netgroups Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG cn=IT Security Specialist,cn=roles,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Netgroups Administrators 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Netgroups Administrators 2019-01-17T11:03:12Z DEBUG [(2, u'member', [u'cn=IT Security Specialist,cn=roles,cn=accounts,dc=local'])] 2019-01-17T11:03:12Z DEBUG Updated 1 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG HBAC Administrator 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG HBAC Administrator 2019-01-17T11:03:12Z DEBUG add: 'cn=IT Security Specialist,cn=roles,cn=accounts,dc=local' to member, current value [] 2019-01-17T11:03:12Z DEBUG add: updated value [u'cn=IT Security Specialist,cn=roles,cn=accounts,dc=local'] 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG cn=IT Security Specialist,cn=roles,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG HBAC Administrator 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG HBAC Administrator 2019-01-17T11:03:12Z DEBUG [(2, u'member', [u'cn=IT Security Specialist,cn=roles,cn=accounts,dc=local'])] 2019-01-17T11:03:12Z DEBUG Updated 1 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Sudo Administrator 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Sudo Administrator 2019-01-17T11:03:12Z DEBUG add: 'cn=IT Security Specialist,cn=roles,cn=accounts,dc=local' to member, current value [] 2019-01-17T11:03:12Z DEBUG add: updated value [u'cn=IT Security Specialist,cn=roles,cn=accounts,dc=local'] 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG cn=IT Security Specialist,cn=roles,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Sudo Administrator 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Sudo Administrator 2019-01-17T11:03:12Z DEBUG [(2, u'member', [u'cn=IT Security Specialist,cn=roles,cn=accounts,dc=local'])] 2019-01-17T11:03:12Z DEBUG Updated 1 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG New entry: cn=Security Architect,cn=roles,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=Security Architect,cn=roles,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Security Architect 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Security Architect 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=Security Architect,cn=roles,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Security Architect 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Security Architect 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=Delegation Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=Delegation Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Delegation Administrator 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Role administration 2019-01-17T11:03:12Z DEBUG add: 'cn=Security Architect,cn=roles,cn=accounts,dc=local' to member, current value [] 2019-01-17T11:03:12Z DEBUG add: updated value [u'cn=Security Architect,cn=roles,cn=accounts,dc=local'] 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=Delegation Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Delegation Administrator 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Role administration 2019-01-17T11:03:12Z DEBUG [(2, u'member', [u'cn=Security Architect,cn=roles,cn=accounts,dc=local'])] 2019-01-17T11:03:12Z DEBUG Updated 1 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=Replication Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=Replication Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG cn=admins,cn=groups,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Replication Administrators 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Replication Administrators 2019-01-17T11:03:12Z DEBUG memberOf: 2019-01-17T11:03:12Z DEBUG cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Modify DNA Range,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Read DNA Range,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG add: 'cn=ipaservers,cn=hostgroups,cn=accounts,dc=local' to member, current value [u'cn=admins,cn=groups,cn=accounts,dc=local'] 2019-01-17T11:03:12Z DEBUG add: updated value [u'cn=admins,cn=groups,cn=accounts,dc=local', u'cn=ipaservers,cn=hostgroups,cn=accounts,dc=local'] 2019-01-17T11:03:12Z DEBUG add: 'cn=Security Architect,cn=roles,cn=accounts,dc=local' to member, current value [u'cn=admins,cn=groups,cn=accounts,dc=local', u'cn=ipaservers,cn=hostgroups,cn=accounts,dc=local'] 2019-01-17T11:03:12Z DEBUG add: updated value [u'cn=admins,cn=groups,cn=accounts,dc=local', u'cn=ipaservers,cn=hostgroups,cn=accounts,dc=local', u'cn=Security Architect,cn=roles,cn=accounts,dc=local'] 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=Replication Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG cn=admins,cn=groups,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG cn=ipaservers,cn=hostgroups,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Replication Administrators 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Replication Administrators 2019-01-17T11:03:12Z DEBUG memberOf: 2019-01-17T11:03:12Z DEBUG cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Modify DNA Range,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Read DNA Range,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG [(0, u'member', [u'cn=ipaservers,cn=hostgroups,cn=accounts,dc=local', u'cn=Security Architect,cn=roles,cn=accounts,dc=local'])] 2019-01-17T11:03:12Z DEBUG Updated 1 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG memberOf: 2019-01-17T11:03:12Z DEBUG cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Write IPA Configuration 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Write IPA Configuration 2019-01-17T11:03:12Z DEBUG add: 'cn=Security Architect,cn=roles,cn=accounts,dc=local' to member, current value [] 2019-01-17T11:03:12Z DEBUG add: updated value [u'cn=Security Architect,cn=roles,cn=accounts,dc=local'] 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG memberOf: 2019-01-17T11:03:12Z DEBUG cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Write IPA Configuration 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Write IPA Configuration 2019-01-17T11:03:12Z DEBUG [(2, u'member', [u'cn=Security Architect,cn=roles,cn=accounts,dc=local'])] 2019-01-17T11:03:12Z DEBUG Updated 1 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Password Policy Administrator 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Password Policy Administrator 2019-01-17T11:03:12Z DEBUG add: 'cn=Security Architect,cn=roles,cn=accounts,dc=local' to member, current value [] 2019-01-17T11:03:12Z DEBUG add: updated value [u'cn=Security Architect,cn=roles,cn=accounts,dc=local'] 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Password Policy Administrator 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Password Policy Administrator 2019-01-17T11:03:12Z DEBUG [(2, u'member', [u'cn=Security Architect,cn=roles,cn=accounts,dc=local'])] 2019-01-17T11:03:12Z DEBUG Updated 1 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG New entry: cn=Enrollment Administrator,cn=roles,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=Enrollment Administrator,cn=roles,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Enrollment Administrator 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Enrollment Administrator responsible for client(host) enrollment 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=Enrollment Administrator,cn=roles,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Enrollment Administrator 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Enrollment Administrator responsible for client(host) enrollment 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=Host Enrollment,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=Host Enrollment,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG cn=admins,cn=groups,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Host Enrollment 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Host Enrollment 2019-01-17T11:03:12Z DEBUG add: 'cn=Enrollment Administrator,cn=roles,cn=accounts,dc=local' to member, current value [u'cn=admins,cn=groups,cn=accounts,dc=local'] 2019-01-17T11:03:12Z DEBUG add: updated value [u'cn=admins,cn=groups,cn=accounts,dc=local', u'cn=Enrollment Administrator,cn=roles,cn=accounts,dc=local'] 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=Host Enrollment,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG cn=admins,cn=groups,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG cn=Enrollment Administrator,cn=roles,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG Host Enrollment 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Host Enrollment 2019-01-17T11:03:12Z DEBUG [(0, u'member', [u'cn=Enrollment Administrator,cn=roles,cn=accounts,dc=local'])] 2019-01-17T11:03:12Z DEBUG Updated 1 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG Parsing update file '/usr/share/ipa/updates/50-7_bit_check.update' 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=7-bit check,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:12Z DEBUG NS7bitAttr 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG 7-bit check 2019-01-17T11:03:12Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:12Z DEBUG 1.3.8.4 2019-01-17T11:03:12Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:12Z DEBUG NS7bitAttr_Init 2019-01-17T11:03:12Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:12Z DEBUG Enforce 7-bit clean attribute values 2019-01-17T11:03:12Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:12Z DEBUG libattr-unique-plugin 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG nsSlapdPlugin 2019-01-17T11:03:12Z DEBUG extensibleObject 2019-01-17T11:03:12Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:12Z DEBUG database 2019-01-17T11:03:12Z DEBUG nsslapd-pluginarg0: 2019-01-17T11:03:12Z DEBUG uid 2019-01-17T11:03:12Z DEBUG nsslapd-pluginarg3: 2019-01-17T11:03:12Z DEBUG dc=local 2019-01-17T11:03:12Z DEBUG nsslapd-pluginarg2: 2019-01-17T11:03:12Z DEBUG , 2019-01-17T11:03:12Z DEBUG nsslapd-pluginarg1: 2019-01-17T11:03:12Z DEBUG mail 2019-01-17T11:03:12Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:12Z DEBUG betxnpreoperation 2019-01-17T11:03:12Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:12Z DEBUG 389 Project 2019-01-17T11:03:12Z DEBUG replace: userpassword not found, skipping 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:12Z DEBUG NS7bitAttr 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG 7-bit check 2019-01-17T11:03:12Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:12Z DEBUG 1.3.8.4 2019-01-17T11:03:12Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:12Z DEBUG NS7bitAttr_Init 2019-01-17T11:03:12Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:12Z DEBUG Enforce 7-bit clean attribute values 2019-01-17T11:03:12Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:12Z DEBUG on 2019-01-17T11:03:12Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:12Z DEBUG libattr-unique-plugin 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG nsSlapdPlugin 2019-01-17T11:03:12Z DEBUG extensibleObject 2019-01-17T11:03:12Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:12Z DEBUG database 2019-01-17T11:03:12Z DEBUG nsslapd-pluginarg0: 2019-01-17T11:03:12Z DEBUG uid 2019-01-17T11:03:12Z DEBUG nsslapd-pluginarg3: 2019-01-17T11:03:12Z DEBUG dc=local 2019-01-17T11:03:12Z DEBUG nsslapd-pluginarg2: 2019-01-17T11:03:12Z DEBUG , 2019-01-17T11:03:12Z DEBUG nsslapd-pluginarg1: 2019-01-17T11:03:12Z DEBUG mail 2019-01-17T11:03:12Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:12Z DEBUG betxnpreoperation 2019-01-17T11:03:12Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:12Z DEBUG 389 Project 2019-01-17T11:03:12Z DEBUG [] 2019-01-17T11:03:12Z DEBUG Updated 0 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG Parsing update file '/usr/share/ipa/updates/50-dogtag10-migration.update' 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=aclResources,o=ipaca 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=aclResources,o=ipaca 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG CertACLS 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG aclResources 2019-01-17T11:03:12Z DEBUG resourceACLS: 2019-01-17T11:03:12Z DEBUG certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete 2019-01-17T11:03:12Z DEBUG certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify 2019-01-17T11:03:12Z DEBUG certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify 2019-01-17T11:03:12Z DEBUG certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify 2019-01-17T11:03:12Z DEBUG certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml 2019-01-17T11:03:12Z DEBUG certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter 2019-01-17T11:03:12Z DEBUG certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log 2019-01-17T11:03:12Z DEBUG certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content 2019-01-17T11:03:12Z DEBUG certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content 2019-01-17T11:03:12Z DEBUG certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify 2019-01-17T11:03:12Z DEBUG certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify 2019-01-17T11:03:12Z DEBUG certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify 2019-01-17T11:03:12Z DEBUG certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets 2019-01-17T11:03:12Z DEBUG certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify 2019-01-17T11:03:12Z DEBUG certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify 2019-01-17T11:03:12Z DEBUG certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify 2019-01-17T11:03:12Z DEBUG certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify 2019-01-17T11:03:12Z DEBUG certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify 2019-01-17T11:03:12Z DEBUG certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory 2019-01-17T11:03:12Z DEBUG certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate 2019-01-17T11:03:12Z DEBUG certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates 2019-01-17T11:03:12Z DEBUG certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests 2019-01-17T11:03:12Z DEBUG certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request 2019-01-17T11:03:12Z DEBUG certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information 2019-01-17T11:03:12Z DEBUG certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests 2019-01-17T11:03:12Z DEBUG certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl 2019-01-17T11:03:12Z DEBUG certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate 2019-01-17T11:03:12Z DEBUG certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates 2019-01-17T11:03:12Z DEBUG certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain 2019-01-17T11:03:12Z DEBUG certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL 2019-01-17T11:03:12Z DEBUG certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request 2019-01-17T11:03:12Z DEBUG certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status 2019-01-17T11:03:12Z DEBUG certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request 2019-01-17T11:03:12Z DEBUG certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate 2019-01-17T11:03:12Z DEBUG certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request 2019-01-17T11:03:12Z DEBUG certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile 2019-01-17T11:03:12Z DEBUG certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles 2019-01-17T11:03:12Z DEBUG certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile 2019-01-17T11:03:12Z DEBUG certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles 2019-01-17T11:03:12Z DEBUG certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles 2019-01-17T11:03:12Z DEBUG certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests 2019-01-17T11:03:12Z DEBUG certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA 2019-01-17T11:03:12Z DEBUG certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics 2019-01-17T11:03:12Z DEBUG certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups 2019-01-17T11:03:12Z DEBUG certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information 2019-01-17T11:03:12Z DEBUG certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent 2019-01-17T11:03:12Z DEBUG certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration. 2019-01-17T11:03:12Z DEBUG certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration. 2019-01-17T11:03:12Z DEBUG certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout 2019-01-17T11:03:12Z DEBUG certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations 2019-01-17T11:03:12Z DEBUG certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations 2019-01-17T11:03:12Z DEBUG certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations 2019-01-17T11:03:12Z DEBUG certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests. 2019-01-17T11:03:12Z DEBUG certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations 2019-01-17T11:03:12Z DEBUG certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities 2019-01-17T11:03:12Z DEBUG certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities 2019-01-17T11:03:12Z DEBUG certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities 2019-01-17T11:03:12Z DEBUG certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles 2019-01-17T11:03:12Z DEBUG certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities 2019-01-17T11:03:12Z DEBUG addifexist: 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout' to resourceACLS, current value [u'certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', u'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', u'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', u'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', u'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', u'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', u'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', u'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', u'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', u'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', u'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', u'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', u'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', u'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', u'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', u'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', u'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', u'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', u'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', u'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', u'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', u'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', u'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', u'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', u'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', u'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', u'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', u'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', u'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', u'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', u'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', u'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', u'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', u'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', u'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', u'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', u'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', u'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', u'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', u'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', u'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', u'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', u'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', u'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', u'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', u'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', u'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', u'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', u'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', u'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', u'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', u'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', u'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', u'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', u'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', u'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', u'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', u'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', u'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities'] 2019-01-17T11:03:12Z DEBUG addifexist: set resourceACLS to [u'certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', u'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', u'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', u'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', u'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', u'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', u'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', u'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', u'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', u'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', u'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', u'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', u'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', u'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', u'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', u'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', u'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', u'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', u'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', u'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', u'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', u'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', u'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', u'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', u'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', u'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', u'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', u'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', u'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', u'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', u'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', u'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', u'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', u'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', u'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', u'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', u'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', u'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', u'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', u'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', u'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', u'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', u'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', u'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', u'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', u'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', u'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', u'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', u'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', u'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', u'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', u'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', u'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', u'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', u'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', u'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', u'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', u'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', u'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', u'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout'] 2019-01-17T11:03:12Z DEBUG addifexist: 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations' to resourceACLS, current value [u'certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', u'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', u'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', u'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', u'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', u'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', u'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', u'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', u'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', u'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', u'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', u'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', u'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', u'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', u'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', u'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', u'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', u'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', u'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', u'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', u'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', u'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', u'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', u'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', u'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', u'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', u'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', u'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', u'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', u'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', u'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', u'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', u'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', u'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', u'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', u'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', u'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', u'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', u'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', u'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', u'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', u'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', u'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', u'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', u'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', u'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', u'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', u'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', u'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', u'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', u'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', u'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', u'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', u'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', u'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', u'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', u'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', u'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', u'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', u'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout'] 2019-01-17T11:03:12Z DEBUG addifexist: set resourceACLS to [u'certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', u'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', u'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', u'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', u'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', u'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', u'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', u'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', u'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', u'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', u'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', u'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', u'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', u'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', u'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', u'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', u'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', u'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', u'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', u'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', u'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', u'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', u'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', u'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', u'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', u'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', u'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', u'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', u'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', u'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', u'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', u'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', u'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', u'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', u'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', u'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', u'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', u'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', u'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', u'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', u'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', u'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', u'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', u'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', u'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', u'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', u'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', u'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', u'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', u'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', u'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', u'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', u'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', u'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', u'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', u'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', u'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', u'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', u'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', u'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', u'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations'] 2019-01-17T11:03:12Z DEBUG addifexist: 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations' to resourceACLS, current value [u'certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', u'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', u'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', u'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', u'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', u'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', u'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', u'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', u'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', u'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', u'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', u'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', u'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', u'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', u'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', u'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', u'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', u'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', u'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', u'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', u'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', u'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', u'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', u'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', u'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', u'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', u'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', u'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', u'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', u'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', u'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', u'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', u'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', u'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', u'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', u'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', u'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', u'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', u'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', u'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', u'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', u'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', u'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', u'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', u'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', u'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', u'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', u'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', u'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', u'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', u'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', u'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', u'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', u'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', u'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', u'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', u'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', u'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', u'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', u'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', u'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations'] 2019-01-17T11:03:12Z DEBUG addifexist: set resourceACLS to [u'certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', u'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', u'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', u'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', u'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', u'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', u'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', u'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', u'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', u'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', u'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', u'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', u'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', u'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', u'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', u'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', u'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', u'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', u'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', u'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', u'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', u'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', u'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', u'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', u'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', u'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', u'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', u'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', u'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', u'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', u'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', u'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', u'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', u'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', u'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', u'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', u'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', u'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', u'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', u'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', u'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', u'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', u'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', u'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', u'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', u'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', u'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', u'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', u'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', u'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', u'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', u'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', u'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', u'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', u'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', u'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', u'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', u'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', u'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', u'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', u'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', u'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations'] 2019-01-17T11:03:12Z DEBUG addifexist: 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations' to resourceACLS, current value [u'certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', u'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', u'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', u'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', u'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', u'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', u'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', u'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', u'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', u'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', u'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', u'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', u'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', u'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', u'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', u'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', u'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', u'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', u'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', u'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', u'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', u'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', u'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', u'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', u'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', u'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', u'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', u'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', u'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', u'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', u'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', u'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', u'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', u'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', u'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', u'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', u'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', u'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', u'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', u'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', u'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', u'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', u'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', u'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', u'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', u'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', u'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', u'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', u'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', u'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', u'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', u'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', u'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', u'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', u'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', u'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', u'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', u'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', u'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', u'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', u'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', u'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations'] 2019-01-17T11:03:12Z DEBUG addifexist: set resourceACLS to [u'certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', u'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', u'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', u'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', u'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', u'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', u'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', u'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', u'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', u'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', u'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', u'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', u'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', u'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', u'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', u'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', u'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', u'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', u'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', u'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', u'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', u'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', u'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', u'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', u'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', u'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', u'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', u'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', u'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', u'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', u'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', u'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', u'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', u'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', u'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', u'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', u'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', u'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', u'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', u'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', u'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', u'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', u'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', u'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', u'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', u'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', u'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', u'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', u'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', u'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', u'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', u'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', u'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', u'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', u'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', u'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', u'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', u'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', u'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', u'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', u'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', u'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', u'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations'] 2019-01-17T11:03:12Z DEBUG addifexist: 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations' to resourceACLS, current value [u'certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', u'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', u'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', u'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', u'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', u'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', u'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', u'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', u'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', u'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', u'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', u'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', u'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', u'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', u'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', u'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', u'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', u'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', u'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', u'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', u'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', u'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', u'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', u'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', u'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', u'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', u'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', u'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', u'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', u'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', u'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', u'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', u'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', u'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', u'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', u'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', u'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', u'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', u'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', u'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', u'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', u'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', u'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', u'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', u'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', u'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', u'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', u'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', u'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', u'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', u'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', u'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', u'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', u'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', u'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', u'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', u'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', u'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', u'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', u'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', u'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', u'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', u'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations'] 2019-01-17T11:03:12Z DEBUG addifexist: set resourceACLS to [u'certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', u'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', u'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', u'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', u'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', u'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', u'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', u'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', u'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', u'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', u'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', u'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', u'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', u'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', u'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', u'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', u'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', u'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', u'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', u'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', u'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', u'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', u'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', u'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', u'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', u'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', u'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', u'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', u'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', u'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', u'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', u'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', u'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', u'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', u'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', u'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', u'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', u'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', u'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', u'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', u'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', u'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', u'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', u'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', u'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', u'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', u'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', u'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', u'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', u'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', u'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', u'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', u'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', u'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', u'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', u'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', u'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', u'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', u'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', u'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', u'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', u'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', u'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', u'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations'] 2019-01-17T11:03:12Z DEBUG replace: certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group":Anybody is allowed to read domain.xml but only Subsystem group is allowed to modify the domain.xml not found, skipping 2019-01-17T11:03:12Z DEBUG replace: certServer.ca.connectorInfo:read,modify:allow (modify,read) group="Enterprise KRA Administrators":Only Enterprise Administrators are allowed to update the connector information not found, skipping 2019-01-17T11:03:12Z DEBUG addifexist: 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles' to resourceACLS, current value [u'certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', u'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', u'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', u'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', u'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', u'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', u'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', u'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', u'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', u'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', u'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', u'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', u'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', u'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', u'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', u'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', u'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', u'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', u'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', u'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', u'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', u'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', u'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', u'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', u'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', u'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', u'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', u'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', u'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', u'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', u'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', u'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', u'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', u'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', u'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', u'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', u'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', u'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', u'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', u'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', u'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', u'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', u'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', u'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', u'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', u'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', u'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', u'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', u'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', u'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', u'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', u'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', u'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', u'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', u'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', u'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', u'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', u'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', u'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', u'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', u'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', u'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', u'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', u'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations'] 2019-01-17T11:03:12Z DEBUG addifexist: set resourceACLS to [u'certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', u'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', u'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', u'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', u'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', u'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', u'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', u'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', u'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', u'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', u'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', u'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', u'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', u'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', u'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', u'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', u'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', u'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', u'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', u'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', u'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', u'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', u'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', u'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', u'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', u'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', u'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', u'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', u'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', u'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', u'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', u'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', u'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', u'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', u'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', u'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', u'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', u'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', u'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', u'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', u'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', u'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', u'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', u'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', u'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', u'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', u'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', u'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', u'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', u'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', u'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', u'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', u'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', u'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', u'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', u'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', u'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', u'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', u'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', u'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', u'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', u'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', u'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', u'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', u'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles'] 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=aclResources,o=ipaca 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG CertACLS 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG aclResources 2019-01-17T11:03:12Z DEBUG resourceACLS: 2019-01-17T11:03:12Z DEBUG certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete 2019-01-17T11:03:12Z DEBUG certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify 2019-01-17T11:03:12Z DEBUG certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify 2019-01-17T11:03:12Z DEBUG certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify 2019-01-17T11:03:12Z DEBUG certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml 2019-01-17T11:03:12Z DEBUG certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter 2019-01-17T11:03:12Z DEBUG certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log 2019-01-17T11:03:12Z DEBUG certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content 2019-01-17T11:03:12Z DEBUG certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content 2019-01-17T11:03:12Z DEBUG certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify 2019-01-17T11:03:12Z DEBUG certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify 2019-01-17T11:03:12Z DEBUG certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify 2019-01-17T11:03:12Z DEBUG certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets 2019-01-17T11:03:12Z DEBUG certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify 2019-01-17T11:03:12Z DEBUG certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify 2019-01-17T11:03:12Z DEBUG certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify 2019-01-17T11:03:12Z DEBUG certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify 2019-01-17T11:03:12Z DEBUG certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify 2019-01-17T11:03:12Z DEBUG certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory 2019-01-17T11:03:12Z DEBUG certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate 2019-01-17T11:03:12Z DEBUG certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates 2019-01-17T11:03:12Z DEBUG certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests 2019-01-17T11:03:12Z DEBUG certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request 2019-01-17T11:03:12Z DEBUG certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information 2019-01-17T11:03:12Z DEBUG certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests 2019-01-17T11:03:12Z DEBUG certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl 2019-01-17T11:03:12Z DEBUG certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate 2019-01-17T11:03:12Z DEBUG certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates 2019-01-17T11:03:12Z DEBUG certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain 2019-01-17T11:03:12Z DEBUG certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL 2019-01-17T11:03:12Z DEBUG certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request 2019-01-17T11:03:12Z DEBUG certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status 2019-01-17T11:03:12Z DEBUG certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request 2019-01-17T11:03:12Z DEBUG certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate 2019-01-17T11:03:12Z DEBUG certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request 2019-01-17T11:03:12Z DEBUG certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile 2019-01-17T11:03:12Z DEBUG certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles 2019-01-17T11:03:12Z DEBUG certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile 2019-01-17T11:03:12Z DEBUG certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles 2019-01-17T11:03:12Z DEBUG certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles 2019-01-17T11:03:12Z DEBUG certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests 2019-01-17T11:03:12Z DEBUG certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA 2019-01-17T11:03:12Z DEBUG certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics 2019-01-17T11:03:12Z DEBUG certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups 2019-01-17T11:03:12Z DEBUG certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information 2019-01-17T11:03:12Z DEBUG certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent 2019-01-17T11:03:12Z DEBUG certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration. 2019-01-17T11:03:12Z DEBUG certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration. 2019-01-17T11:03:12Z DEBUG certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout 2019-01-17T11:03:12Z DEBUG certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations 2019-01-17T11:03:12Z DEBUG certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations 2019-01-17T11:03:12Z DEBUG certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations 2019-01-17T11:03:12Z DEBUG certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests. 2019-01-17T11:03:12Z DEBUG certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations 2019-01-17T11:03:12Z DEBUG certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities 2019-01-17T11:03:12Z DEBUG certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities 2019-01-17T11:03:12Z DEBUG certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities 2019-01-17T11:03:12Z DEBUG certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles 2019-01-17T11:03:12Z DEBUG certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities 2019-01-17T11:03:12Z DEBUG certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout 2019-01-17T11:03:12Z DEBUG certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations 2019-01-17T11:03:12Z DEBUG certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations 2019-01-17T11:03:12Z DEBUG certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations 2019-01-17T11:03:12Z DEBUG certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations 2019-01-17T11:03:12Z DEBUG certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles 2019-01-17T11:03:12Z DEBUG [] 2019-01-17T11:03:12Z DEBUG Updated 0 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG Parsing update file '/usr/share/ipa/updates/50-externalmembers.update' 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:03:12Z DEBUG objectclass=posixGroup 2019-01-17T11:03:12Z DEBUG gidNumber=%{gidNumber} 2019-01-17T11:03:12Z DEBUG memberUid=%{memberUid} 2019-01-17T11:03:12Z DEBUG memberUid=%deref_r("member","uid") 2019-01-17T11:03:12Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:03:12Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","") 2019-01-17T11:03:12Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2019-01-17T11:03:12Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:03:12Z DEBUG ipaexternalmember=%deref_r("member","ipaexternalmember") 2019-01-17T11:03:12Z DEBUG objectclass=ipaexternalgroup 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG groups 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG extensibleObject 2019-01-17T11:03:12Z DEBUG schema-compat-container-rdn: 2019-01-17T11:03:12Z DEBUG cn=groups 2019-01-17T11:03:12Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:03:12Z DEBUG dc=local 2019-01-17T11:03:12Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:03:12Z DEBUG cn=%{cn} 2019-01-17T11:03:12Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:03:12Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:12Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:12Z DEBUG schema-compat-search-filter: 2019-01-17T11:03:12Z DEBUG objectclass=posixGroup 2019-01-17T11:03:12Z DEBUG schema-compat-search-base: 2019-01-17T11:03:12Z DEBUG cn=groups, cn=accounts, dc=local 2019-01-17T11:03:12Z DEBUG schema-compat-container-group: 2019-01-17T11:03:12Z DEBUG cn=compat, dc=local 2019-01-17T11:03:12Z DEBUG addifexist: 'ipaexternalmember=%deref_r("member","ipaexternalmember")' to schema-compat-entry-attribute, current value [u'objectclass=posixGroup', u'gidNumber=%{gidNumber}', u'memberUid=%{memberUid}', u'memberUid=%deref_r("member","uid")', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'ipaexternalmember=%deref_r("member","ipaexternalmember")', u'objectclass=ipaexternalgroup'] 2019-01-17T11:03:12Z DEBUG addifexist: set schema-compat-entry-attribute to [u'objectclass=posixGroup', u'gidNumber=%{gidNumber}', u'memberUid=%{memberUid}', u'memberUid=%deref_r("member","uid")', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'ipaexternalmember=%deref_r("member","ipaexternalmember")', u'objectclass=ipaexternalgroup', u'ipaexternalmember=%deref_r("member","ipaexternalmember")'] 2019-01-17T11:03:12Z DEBUG addifexist: 'objectclass=ipaexternalgroup' to schema-compat-entry-attribute, current value [u'objectclass=posixGroup', u'gidNumber=%{gidNumber}', u'memberUid=%{memberUid}', u'memberUid=%deref_r("member","uid")', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'ipaexternalmember=%deref_r("member","ipaexternalmember")', u'objectclass=ipaexternalgroup', u'ipaexternalmember=%deref_r("member","ipaexternalmember")'] 2019-01-17T11:03:12Z DEBUG addifexist: set schema-compat-entry-attribute to [u'objectclass=posixGroup', u'gidNumber=%{gidNumber}', u'memberUid=%{memberUid}', u'memberUid=%deref_r("member","uid")', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'ipaexternalmember=%deref_r("member","ipaexternalmember")', u'objectclass=ipaexternalgroup', u'ipaexternalmember=%deref_r("member","ipaexternalmember")', u'objectclass=ipaexternalgroup'] 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:03:12Z DEBUG objectclass=posixGroup 2019-01-17T11:03:12Z DEBUG gidNumber=%{gidNumber} 2019-01-17T11:03:12Z DEBUG memberUid=%{memberUid} 2019-01-17T11:03:12Z DEBUG memberUid=%deref_r("member","uid") 2019-01-17T11:03:12Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:03:12Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","") 2019-01-17T11:03:12Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2019-01-17T11:03:12Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:03:12Z DEBUG ipaexternalmember=%deref_r("member","ipaexternalmember") 2019-01-17T11:03:12Z DEBUG objectclass=ipaexternalgroup 2019-01-17T11:03:12Z DEBUG ipaexternalmember=%deref_r("member","ipaexternalmember") 2019-01-17T11:03:12Z DEBUG objectclass=ipaexternalgroup 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG groups 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG extensibleObject 2019-01-17T11:03:12Z DEBUG schema-compat-container-rdn: 2019-01-17T11:03:12Z DEBUG cn=groups 2019-01-17T11:03:12Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:03:12Z DEBUG dc=local 2019-01-17T11:03:12Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:12Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:03:12Z DEBUG cn=%{cn} 2019-01-17T11:03:12Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:03:12Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:12Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:12Z DEBUG schema-compat-search-filter: 2019-01-17T11:03:12Z DEBUG objectclass=posixGroup 2019-01-17T11:03:12Z DEBUG schema-compat-search-base: 2019-01-17T11:03:12Z DEBUG cn=groups, cn=accounts, dc=local 2019-01-17T11:03:12Z DEBUG schema-compat-container-group: 2019-01-17T11:03:12Z DEBUG cn=compat, dc=local 2019-01-17T11:03:12Z DEBUG [] 2019-01-17T11:03:12Z DEBUG Updated 0 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG Parsing update file '/usr/share/ipa/updates/50-groupuuid.update' 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=admins,cn=groups,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=admins,cn=groups,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG admins 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG posixgroup 2019-01-17T11:03:12Z DEBUG ipausergroup 2019-01-17T11:03:12Z DEBUG ipaobject 2019-01-17T11:03:12Z DEBUG nestedGroup 2019-01-17T11:03:12Z DEBUG memberOf: 2019-01-17T11:03:12Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Modify DNA Range,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Read DNA Range,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Host Enrollment,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG uid=admin,cn=users,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG gidNumber: 2019-01-17T11:03:12Z DEBUG 353600000 2019-01-17T11:03:12Z DEBUG ipaUniqueID: 2019-01-17T11:03:12Z DEBUG 974f8d20-1a43-11e9-b3f7-5254007fd04f 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Account administrators group 2019-01-17T11:03:12Z DEBUG add: 'ipaobject' to objectclass, current value [u'top', u'groupofnames', u'posixgroup', u'ipausergroup', u'ipaobject', u'nestedGroup'] 2019-01-17T11:03:12Z DEBUG add: updated value [u'top', u'groupofnames', u'posixgroup', u'ipausergroup', u'nestedGroup', u'ipaobject'] 2019-01-17T11:03:12Z DEBUG addifnew: 'autogenerate' to ipaUniqueID, current value [u'974f8d20-1a43-11e9-b3f7-5254007fd04f'] 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=admins,cn=groups,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG admins 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG posixgroup 2019-01-17T11:03:12Z DEBUG ipausergroup 2019-01-17T11:03:12Z DEBUG nestedGroup 2019-01-17T11:03:12Z DEBUG ipaobject 2019-01-17T11:03:12Z DEBUG memberOf: 2019-01-17T11:03:12Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Modify DNA Range,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Read DNA Range,cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=Host Enrollment,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG uid=admin,cn=users,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG gidNumber: 2019-01-17T11:03:12Z DEBUG 353600000 2019-01-17T11:03:12Z DEBUG ipaUniqueID: 2019-01-17T11:03:12Z DEBUG 974f8d20-1a43-11e9-b3f7-5254007fd04f 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Account administrators group 2019-01-17T11:03:12Z DEBUG [] 2019-01-17T11:03:12Z DEBUG Updated 0 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=ipausers,cn=groups,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=ipausers,cn=groups,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG ipausergroup 2019-01-17T11:03:12Z DEBUG ipaobject 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG ipausers 2019-01-17T11:03:12Z DEBUG ipaUniqueID: 2019-01-17T11:03:12Z DEBUG 97591836-1a43-11e9-a079-5254007fd04f 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Default group for all users 2019-01-17T11:03:12Z DEBUG add: 'ipaobject' to objectclass, current value [u'top', u'groupofnames', u'nestedgroup', u'ipausergroup', u'ipaobject'] 2019-01-17T11:03:12Z DEBUG add: updated value [u'top', u'groupofnames', u'nestedgroup', u'ipausergroup', u'ipaobject'] 2019-01-17T11:03:12Z DEBUG addifnew: 'autogenerate' to ipaUniqueID, current value [u'97591836-1a43-11e9-a079-5254007fd04f'] 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=ipausers,cn=groups,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG nestedgroup 2019-01-17T11:03:12Z DEBUG ipausergroup 2019-01-17T11:03:12Z DEBUG ipaobject 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG ipausers 2019-01-17T11:03:12Z DEBUG ipaUniqueID: 2019-01-17T11:03:12Z DEBUG 97591836-1a43-11e9-a079-5254007fd04f 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Default group for all users 2019-01-17T11:03:12Z DEBUG [] 2019-01-17T11:03:12Z DEBUG Updated 0 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=editors,cn=groups,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=editors,cn=groups,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG posixgroup 2019-01-17T11:03:12Z DEBUG ipausergroup 2019-01-17T11:03:12Z DEBUG ipaobject 2019-01-17T11:03:12Z DEBUG nestedGroup 2019-01-17T11:03:12Z DEBUG gidNumber: 2019-01-17T11:03:12Z DEBUG 353600002 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG editors 2019-01-17T11:03:12Z DEBUG ipaUniqueID: 2019-01-17T11:03:12Z DEBUG 975a17cc-1a43-11e9-9b21-5254007fd04f 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Limited admins who can edit other users 2019-01-17T11:03:12Z DEBUG add: 'ipaobject' to objectclass, current value [u'top', u'groupofnames', u'posixgroup', u'ipausergroup', u'ipaobject', u'nestedGroup'] 2019-01-17T11:03:12Z DEBUG add: updated value [u'top', u'groupofnames', u'posixgroup', u'ipausergroup', u'nestedGroup', u'ipaobject'] 2019-01-17T11:03:12Z DEBUG addifnew: 'autogenerate' to ipaUniqueID, current value [u'975a17cc-1a43-11e9-9b21-5254007fd04f'] 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=editors,cn=groups,cn=accounts,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG groupofnames 2019-01-17T11:03:12Z DEBUG posixgroup 2019-01-17T11:03:12Z DEBUG ipausergroup 2019-01-17T11:03:12Z DEBUG nestedGroup 2019-01-17T11:03:12Z DEBUG ipaobject 2019-01-17T11:03:12Z DEBUG gidNumber: 2019-01-17T11:03:12Z DEBUG 353600002 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG editors 2019-01-17T11:03:12Z DEBUG ipaUniqueID: 2019-01-17T11:03:12Z DEBUG 975a17cc-1a43-11e9-9b21-5254007fd04f 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Limited admins who can edit other users 2019-01-17T11:03:12Z DEBUG [] 2019-01-17T11:03:12Z DEBUG Updated 0 2019-01-17T11:03:12Z DEBUG Done 2019-01-17T11:03:12Z DEBUG Parsing update file '/usr/share/ipa/updates/50-hbacservice.update' 2019-01-17T11:03:12Z DEBUG New entry: cn=crond,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=crond,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:03:12Z DEBUG objectclass: 2019-01-17T11:03:12Z DEBUG ipahbacservice 2019-01-17T11:03:12Z DEBUG ipaobject 2019-01-17T11:03:12Z DEBUG ipauniqueid: 2019-01-17T11:03:12Z DEBUG autogenerate 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG crond 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG crond 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=crond,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:03:12Z DEBUG objectclass: 2019-01-17T11:03:12Z DEBUG ipahbacservice 2019-01-17T11:03:12Z DEBUG ipaobject 2019-01-17T11:03:12Z DEBUG ipauniqueid: 2019-01-17T11:03:12Z DEBUG autogenerate 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG crond 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG crond 2019-01-17T11:03:12Z DEBUG New entry: cn=vsftpd,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=vsftpd,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:03:12Z DEBUG objectclass: 2019-01-17T11:03:12Z DEBUG ipahbacservice 2019-01-17T11:03:12Z DEBUG ipaobject 2019-01-17T11:03:12Z DEBUG ipauniqueid: 2019-01-17T11:03:12Z DEBUG autogenerate 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG vsftpd 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG vsftpd 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=vsftpd,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:03:12Z DEBUG objectclass: 2019-01-17T11:03:12Z DEBUG ipahbacservice 2019-01-17T11:03:12Z DEBUG ipaobject 2019-01-17T11:03:12Z DEBUG ipauniqueid: 2019-01-17T11:03:12Z DEBUG autogenerate 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG vsftpd 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG vsftpd 2019-01-17T11:03:12Z DEBUG New entry: cn=proftpd,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=proftpd,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:03:12Z DEBUG objectclass: 2019-01-17T11:03:12Z DEBUG ipahbacservice 2019-01-17T11:03:12Z DEBUG ipaobject 2019-01-17T11:03:12Z DEBUG ipauniqueid: 2019-01-17T11:03:12Z DEBUG autogenerate 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG proftpd 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG proftpd 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=proftpd,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:03:12Z DEBUG objectclass: 2019-01-17T11:03:12Z DEBUG ipahbacservice 2019-01-17T11:03:12Z DEBUG ipaobject 2019-01-17T11:03:12Z DEBUG ipauniqueid: 2019-01-17T11:03:12Z DEBUG autogenerate 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG proftpd 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG proftpd 2019-01-17T11:03:12Z DEBUG New entry: cn=pure-ftpd,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=pure-ftpd,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:03:12Z DEBUG objectclass: 2019-01-17T11:03:12Z DEBUG ipahbacservice 2019-01-17T11:03:12Z DEBUG ipaobject 2019-01-17T11:03:12Z DEBUG ipauniqueid: 2019-01-17T11:03:12Z DEBUG autogenerate 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG pure-ftpd 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG pure-ftpd 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=pure-ftpd,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:03:12Z DEBUG objectclass: 2019-01-17T11:03:12Z DEBUG ipahbacservice 2019-01-17T11:03:12Z DEBUG ipaobject 2019-01-17T11:03:12Z DEBUG ipauniqueid: 2019-01-17T11:03:12Z DEBUG autogenerate 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG pure-ftpd 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG pure-ftpd 2019-01-17T11:03:12Z DEBUG New entry: cn=gssftp,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=gssftp,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:03:12Z DEBUG objectclass: 2019-01-17T11:03:12Z DEBUG ipahbacservice 2019-01-17T11:03:12Z DEBUG ipaobject 2019-01-17T11:03:12Z DEBUG ipauniqueid: 2019-01-17T11:03:12Z DEBUG autogenerate 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG gssftp 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG gssftp 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=gssftp,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:03:12Z DEBUG objectclass: 2019-01-17T11:03:12Z DEBUG ipahbacservice 2019-01-17T11:03:12Z DEBUG ipaobject 2019-01-17T11:03:12Z DEBUG ipauniqueid: 2019-01-17T11:03:12Z DEBUG autogenerate 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG gssftp 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG gssftp 2019-01-17T11:03:12Z DEBUG New entry: cn=ftp,cn=hbacservicegroups,cn=hbac,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:12Z DEBUG dn: cn=ftp,cn=hbacservicegroups,cn=hbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG ipaobject 2019-01-17T11:03:12Z DEBUG ipahbacservicegroup 2019-01-17T11:03:12Z DEBUG nestedGroup 2019-01-17T11:03:12Z DEBUG groupOfNames 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG cn=ftp,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=proftpd,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=pure-ftpd,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=vsftpd,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=gssftp,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Default group of ftp related services 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG ftp 2019-01-17T11:03:12Z DEBUG ipauniqueid: 2019-01-17T11:03:12Z DEBUG autogenerate 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Final value after applying updates 2019-01-17T11:03:12Z DEBUG dn: cn=ftp,cn=hbacservicegroups,cn=hbac,dc=local 2019-01-17T11:03:12Z DEBUG objectClass: 2019-01-17T11:03:12Z DEBUG ipaobject 2019-01-17T11:03:12Z DEBUG ipahbacservicegroup 2019-01-17T11:03:12Z DEBUG nestedGroup 2019-01-17T11:03:12Z DEBUG groupOfNames 2019-01-17T11:03:12Z DEBUG top 2019-01-17T11:03:12Z DEBUG member: 2019-01-17T11:03:12Z DEBUG cn=ftp,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=proftpd,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=pure-ftpd,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=vsftpd,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:03:12Z DEBUG cn=gssftp,cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:03:12Z DEBUG description: 2019-01-17T11:03:12Z DEBUG Default group of ftp related services 2019-01-17T11:03:12Z DEBUG cn: 2019-01-17T11:03:12Z DEBUG ftp 2019-01-17T11:03:12Z DEBUG ipauniqueid: 2019-01-17T11:03:12Z DEBUG autogenerate 2019-01-17T11:03:12Z DEBUG Parsing update file '/usr/share/ipa/updates/50-ipaconfig.update' 2019-01-17T11:03:12Z DEBUG Updating existing entry: cn=ipaConfig,cn=etc,dc=local 2019-01-17T11:03:12Z DEBUG --------------------------------------------- 2019-01-17T11:03:12Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=ipaConfig,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG ipaDefaultLoginShell: 2019-01-17T11:03:13Z DEBUG /bin/sh 2019-01-17T11:03:13Z DEBUG ipaCertificateSubjectBase: 2019-01-17T11:03:13Z DEBUG O=LOCAL 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG ipaConfig 2019-01-17T11:03:13Z DEBUG ipaSELinuxUserMapDefault: 2019-01-17T11:03:13Z DEBUG unconfined_u:s0-s0:c0.c1023 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG nsContainer 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG ipaGuiConfig 2019-01-17T11:03:13Z DEBUG ipaConfigObject 2019-01-17T11:03:13Z DEBUG ipaHomesRootDir: 2019-01-17T11:03:13Z DEBUG /home 2019-01-17T11:03:13Z DEBUG ipaPwdExpAdvNotify: 2019-01-17T11:03:13Z DEBUG 4 2019-01-17T11:03:13Z DEBUG ipaUserObjectClasses: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG person 2019-01-17T11:03:13Z DEBUG organizationalperson 2019-01-17T11:03:13Z DEBUG inetorgperson 2019-01-17T11:03:13Z DEBUG inetuser 2019-01-17T11:03:13Z DEBUG posixaccount 2019-01-17T11:03:13Z DEBUG krbprincipalaux 2019-01-17T11:03:13Z DEBUG krbticketpolicyaux 2019-01-17T11:03:13Z DEBUG ipaobject 2019-01-17T11:03:13Z DEBUG ipasshuser 2019-01-17T11:03:13Z DEBUG ipaGroupSearchFields: 2019-01-17T11:03:13Z DEBUG cn,description 2019-01-17T11:03:13Z DEBUG ipaMigrationEnabled: 2019-01-17T11:03:13Z DEBUG FALSE 2019-01-17T11:03:13Z DEBUG ipaDefaultPrimaryGroup: 2019-01-17T11:03:13Z DEBUG ipausers 2019-01-17T11:03:13Z DEBUG ipaSearchTimeLimit: 2019-01-17T11:03:13Z DEBUG 2 2019-01-17T11:03:13Z DEBUG ipaGroupObjectClasses: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG groupofnames 2019-01-17T11:03:13Z DEBUG nestedgroup 2019-01-17T11:03:13Z DEBUG ipausergroup 2019-01-17T11:03:13Z DEBUG ipaobject 2019-01-17T11:03:13Z DEBUG ipaDefaultEmailDomain: 2019-01-17T11:03:13Z DEBUG local 2019-01-17T11:03:13Z DEBUG ipaSearchRecordsLimit: 2019-01-17T11:03:13Z DEBUG 100 2019-01-17T11:03:13Z DEBUG ipaSELinuxUserMapOrder: 2019-01-17T11:03:13Z DEBUG guest_u:s0$xguest_u:s0$user_u:s0$staff_u:s0-s0:c0.c1023$unconfined_u:s0-s0:c0.c1023 2019-01-17T11:03:13Z DEBUG ipaConfigString: 2019-01-17T11:03:13Z DEBUG AllowNThash 2019-01-17T11:03:13Z DEBUG KDC:Disable Last Success 2019-01-17T11:03:13Z DEBUG ipaMaxUsernameLength: 2019-01-17T11:03:13Z DEBUG 32 2019-01-17T11:03:13Z DEBUG ipaUserSearchFields: 2019-01-17T11:03:13Z DEBUG uid,givenname,sn,telephonenumber,ou,title 2019-01-17T11:03:13Z DEBUG replace: guest_u:s0$xguest_u:s0$user_u:s0-s0:c0.c1023$staff_u:s0-s0:c0.c1023$unconfined_u:s0-s0:c0.c1023 not found, skipping 2019-01-17T11:03:13Z DEBUG add: 'unconfined_u:s0-s0:c0.c1023' to ipaSELinuxUserMapDefault, current value [u'unconfined_u:s0-s0:c0.c1023'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'unconfined_u:s0-s0:c0.c1023'] 2019-01-17T11:03:13Z DEBUG add: 'ipasshuser' to ipaUserObjectClasses, current value [u'top', u'person', u'organizationalperson', u'inetorgperson', u'inetuser', u'posixaccount', u'krbprincipalaux', u'krbticketpolicyaux', u'ipaobject', u'ipasshuser'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'top', u'person', u'organizationalperson', u'inetorgperson', u'inetuser', u'posixaccount', u'krbprincipalaux', u'krbticketpolicyaux', u'ipaobject', u'ipasshuser'] 2019-01-17T11:03:13Z DEBUG remove: 'AllowLMhash' from ipaConfigString, current value [u'AllowNThash', u'KDC:Disable Last Success'] 2019-01-17T11:03:13Z DEBUG remove: 'AllowLMhash' not in ipaConfigString 2019-01-17T11:03:13Z DEBUG add: 'ipaUserAuthTypeClass' to objectClass, current value [u'nsContainer', u'top', u'ipaGuiConfig', u'ipaConfigObject'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'nsContainer', u'top', u'ipaGuiConfig', u'ipaConfigObject', u'ipaUserAuthTypeClass'] 2019-01-17T11:03:13Z DEBUG add: 'ipaNameResolutionData' to objectClass, current value [u'nsContainer', u'top', u'ipaGuiConfig', u'ipaConfigObject', u'ipaUserAuthTypeClass'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'nsContainer', u'top', u'ipaGuiConfig', u'ipaConfigObject', u'ipaUserAuthTypeClass', u'ipaNameResolutionData'] 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=ipaConfig,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG ipaDefaultLoginShell: 2019-01-17T11:03:13Z DEBUG /bin/sh 2019-01-17T11:03:13Z DEBUG ipaCertificateSubjectBase: 2019-01-17T11:03:13Z DEBUG O=LOCAL 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG ipaConfig 2019-01-17T11:03:13Z DEBUG ipaSELinuxUserMapDefault: 2019-01-17T11:03:13Z DEBUG unconfined_u:s0-s0:c0.c1023 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG nsContainer 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG ipaGuiConfig 2019-01-17T11:03:13Z DEBUG ipaConfigObject 2019-01-17T11:03:13Z DEBUG ipaUserAuthTypeClass 2019-01-17T11:03:13Z DEBUG ipaNameResolutionData 2019-01-17T11:03:13Z DEBUG ipaHomesRootDir: 2019-01-17T11:03:13Z DEBUG /home 2019-01-17T11:03:13Z DEBUG ipaPwdExpAdvNotify: 2019-01-17T11:03:13Z DEBUG 4 2019-01-17T11:03:13Z DEBUG ipaUserObjectClasses: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG person 2019-01-17T11:03:13Z DEBUG organizationalperson 2019-01-17T11:03:13Z DEBUG inetorgperson 2019-01-17T11:03:13Z DEBUG inetuser 2019-01-17T11:03:13Z DEBUG posixaccount 2019-01-17T11:03:13Z DEBUG krbprincipalaux 2019-01-17T11:03:13Z DEBUG krbticketpolicyaux 2019-01-17T11:03:13Z DEBUG ipaobject 2019-01-17T11:03:13Z DEBUG ipasshuser 2019-01-17T11:03:13Z DEBUG ipaGroupSearchFields: 2019-01-17T11:03:13Z DEBUG cn,description 2019-01-17T11:03:13Z DEBUG ipaMigrationEnabled: 2019-01-17T11:03:13Z DEBUG FALSE 2019-01-17T11:03:13Z DEBUG ipaDefaultPrimaryGroup: 2019-01-17T11:03:13Z DEBUG ipausers 2019-01-17T11:03:13Z DEBUG ipaSearchTimeLimit: 2019-01-17T11:03:13Z DEBUG 2 2019-01-17T11:03:13Z DEBUG ipaGroupObjectClasses: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG groupofnames 2019-01-17T11:03:13Z DEBUG nestedgroup 2019-01-17T11:03:13Z DEBUG ipausergroup 2019-01-17T11:03:13Z DEBUG ipaobject 2019-01-17T11:03:13Z DEBUG ipaDefaultEmailDomain: 2019-01-17T11:03:13Z DEBUG local 2019-01-17T11:03:13Z DEBUG ipaSearchRecordsLimit: 2019-01-17T11:03:13Z DEBUG 100 2019-01-17T11:03:13Z DEBUG ipaSELinuxUserMapOrder: 2019-01-17T11:03:13Z DEBUG guest_u:s0$xguest_u:s0$user_u:s0$staff_u:s0-s0:c0.c1023$unconfined_u:s0-s0:c0.c1023 2019-01-17T11:03:13Z DEBUG ipaConfigString: 2019-01-17T11:03:13Z DEBUG AllowNThash 2019-01-17T11:03:13Z DEBUG KDC:Disable Last Success 2019-01-17T11:03:13Z DEBUG ipaMaxUsernameLength: 2019-01-17T11:03:13Z DEBUG 32 2019-01-17T11:03:13Z DEBUG ipaUserSearchFields: 2019-01-17T11:03:13Z DEBUG uid,givenname,sn,telephonenumber,ou,title 2019-01-17T11:03:13Z DEBUG [(0, u'objectClass', [u'ipaUserAuthTypeClass', u'ipaNameResolutionData'])] 2019-01-17T11:03:13Z DEBUG Updated 1 2019-01-17T11:03:13Z DEBUG Done 2019-01-17T11:03:13Z DEBUG Parsing update file '/usr/share/ipa/updates/50-krbenctypes.update' 2019-01-17T11:03:13Z DEBUG Updating existing entry: cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:03:13Z DEBUG krbSubTrees: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG LOCAL 2019-01-17T11:03:13Z DEBUG krbDefaultEncSaltTypes: 2019-01-17T11:03:13Z DEBUG aes256-cts:special 2019-01-17T11:03:13Z DEBUG aes128-cts:special 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG krbrealmcontainer 2019-01-17T11:03:13Z DEBUG krbticketpolicyaux 2019-01-17T11:03:13Z DEBUG krbSearchScope: 2019-01-17T11:03:13Z DEBUG 2 2019-01-17T11:03:13Z DEBUG krbSupportedEncSaltTypes: 2019-01-17T11:03:13Z DEBUG aes256-cts:normal 2019-01-17T11:03:13Z DEBUG aes256-cts:special 2019-01-17T11:03:13Z DEBUG aes128-cts:normal 2019-01-17T11:03:13Z DEBUG aes128-cts:special 2019-01-17T11:03:13Z DEBUG des3-hmac-sha1:normal 2019-01-17T11:03:13Z DEBUG des3-hmac-sha1:special 2019-01-17T11:03:13Z DEBUG arcfour-hmac:normal 2019-01-17T11:03:13Z DEBUG arcfour-hmac:special 2019-01-17T11:03:13Z DEBUG camellia128-cts-cmac:normal 2019-01-17T11:03:13Z DEBUG camellia128-cts-cmac:special 2019-01-17T11:03:13Z DEBUG camellia256-cts-cmac:normal 2019-01-17T11:03:13Z DEBUG camellia256-cts-cmac:special 2019-01-17T11:03:13Z DEBUG krbMaxTicketLife: 2019-01-17T11:03:13Z DEBUG 86400 2019-01-17T11:03:13Z DEBUG krbMKey: 2019-01-17T11:03:13Z DEBUG XXXXXXXX 2019-01-17T11:03:13Z DEBUG krbPwdPolicyReference: 2019-01-17T11:03:13Z DEBUG cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:03:13Z DEBUG krbMaxRenewableAge: 2019-01-17T11:03:13Z DEBUG 604800 2019-01-17T11:03:13Z DEBUG add: 'camellia128-cts-cmac:normal' to krbSupportedEncSaltTypes, current value [u'aes256-cts:normal', u'aes256-cts:special', u'aes128-cts:normal', u'aes128-cts:special', u'des3-hmac-sha1:normal', u'des3-hmac-sha1:special', u'arcfour-hmac:normal', u'arcfour-hmac:special', u'camellia128-cts-cmac:normal', u'camellia128-cts-cmac:special', u'camellia256-cts-cmac:normal', u'camellia256-cts-cmac:special'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'aes256-cts:normal', u'aes256-cts:special', u'aes128-cts:normal', u'aes128-cts:special', u'des3-hmac-sha1:normal', u'des3-hmac-sha1:special', u'arcfour-hmac:normal', u'arcfour-hmac:special', u'camellia128-cts-cmac:special', u'camellia256-cts-cmac:normal', u'camellia256-cts-cmac:special', u'camellia128-cts-cmac:normal'] 2019-01-17T11:03:13Z DEBUG add: 'camellia128-cts-cmac:special' to krbSupportedEncSaltTypes, current value [u'aes256-cts:normal', u'aes256-cts:special', u'aes128-cts:normal', u'aes128-cts:special', u'des3-hmac-sha1:normal', u'des3-hmac-sha1:special', u'arcfour-hmac:normal', u'arcfour-hmac:special', u'camellia128-cts-cmac:special', u'camellia256-cts-cmac:normal', u'camellia256-cts-cmac:special', u'camellia128-cts-cmac:normal'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'aes256-cts:normal', u'aes256-cts:special', u'aes128-cts:normal', u'aes128-cts:special', u'des3-hmac-sha1:normal', u'des3-hmac-sha1:special', u'arcfour-hmac:normal', u'arcfour-hmac:special', u'camellia256-cts-cmac:normal', u'camellia256-cts-cmac:special', u'camellia128-cts-cmac:normal', u'camellia128-cts-cmac:special'] 2019-01-17T11:03:13Z DEBUG add: 'camellia256-cts-cmac:normal' to krbSupportedEncSaltTypes, current value [u'aes256-cts:normal', u'aes256-cts:special', u'aes128-cts:normal', u'aes128-cts:special', u'des3-hmac-sha1:normal', u'des3-hmac-sha1:special', u'arcfour-hmac:normal', u'arcfour-hmac:special', u'camellia256-cts-cmac:normal', u'camellia256-cts-cmac:special', u'camellia128-cts-cmac:normal', u'camellia128-cts-cmac:special'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'aes256-cts:normal', u'aes256-cts:special', u'aes128-cts:normal', u'aes128-cts:special', u'des3-hmac-sha1:normal', u'des3-hmac-sha1:special', u'arcfour-hmac:normal', u'arcfour-hmac:special', u'camellia256-cts-cmac:special', u'camellia128-cts-cmac:normal', u'camellia128-cts-cmac:special', u'camellia256-cts-cmac:normal'] 2019-01-17T11:03:13Z DEBUG add: 'camellia256-cts-cmac:special' to krbSupportedEncSaltTypes, current value [u'aes256-cts:normal', u'aes256-cts:special', u'aes128-cts:normal', u'aes128-cts:special', u'des3-hmac-sha1:normal', u'des3-hmac-sha1:special', u'arcfour-hmac:normal', u'arcfour-hmac:special', u'camellia256-cts-cmac:special', u'camellia128-cts-cmac:normal', u'camellia128-cts-cmac:special', u'camellia256-cts-cmac:normal'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'aes256-cts:normal', u'aes256-cts:special', u'aes128-cts:normal', u'aes128-cts:special', u'des3-hmac-sha1:normal', u'des3-hmac-sha1:special', u'arcfour-hmac:normal', u'arcfour-hmac:special', u'camellia128-cts-cmac:normal', u'camellia128-cts-cmac:special', u'camellia256-cts-cmac:normal', u'camellia256-cts-cmac:special'] 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:03:13Z DEBUG krbSubTrees: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG LOCAL 2019-01-17T11:03:13Z DEBUG krbDefaultEncSaltTypes: 2019-01-17T11:03:13Z DEBUG aes256-cts:special 2019-01-17T11:03:13Z DEBUG aes128-cts:special 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG krbrealmcontainer 2019-01-17T11:03:13Z DEBUG krbticketpolicyaux 2019-01-17T11:03:13Z DEBUG krbSearchScope: 2019-01-17T11:03:13Z DEBUG 2 2019-01-17T11:03:13Z DEBUG krbSupportedEncSaltTypes: 2019-01-17T11:03:13Z DEBUG aes256-cts:normal 2019-01-17T11:03:13Z DEBUG aes256-cts:special 2019-01-17T11:03:13Z DEBUG aes128-cts:normal 2019-01-17T11:03:13Z DEBUG aes128-cts:special 2019-01-17T11:03:13Z DEBUG des3-hmac-sha1:normal 2019-01-17T11:03:13Z DEBUG des3-hmac-sha1:special 2019-01-17T11:03:13Z DEBUG arcfour-hmac:normal 2019-01-17T11:03:13Z DEBUG arcfour-hmac:special 2019-01-17T11:03:13Z DEBUG camellia128-cts-cmac:normal 2019-01-17T11:03:13Z DEBUG camellia128-cts-cmac:special 2019-01-17T11:03:13Z DEBUG camellia256-cts-cmac:normal 2019-01-17T11:03:13Z DEBUG camellia256-cts-cmac:special 2019-01-17T11:03:13Z DEBUG krbMaxTicketLife: 2019-01-17T11:03:13Z DEBUG 86400 2019-01-17T11:03:13Z DEBUG krbMKey: 2019-01-17T11:03:13Z DEBUG XXXXXXXX 2019-01-17T11:03:13Z DEBUG krbPwdPolicyReference: 2019-01-17T11:03:13Z DEBUG cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:03:13Z DEBUG krbMaxRenewableAge: 2019-01-17T11:03:13Z DEBUG 604800 2019-01-17T11:03:13Z DEBUG [] 2019-01-17T11:03:13Z DEBUG Updated 0 2019-01-17T11:03:13Z DEBUG Done 2019-01-17T11:03:13Z DEBUG Parsing update file '/usr/share/ipa/updates/50-nis.update' 2019-01-17T11:03:13Z DEBUG Executing upgrade plugin: update_nis_configuration 2019-01-17T11:03:13Z DEBUG raw: update_nis_configuration 2019-01-17T11:03:13Z DEBUG Skipping NIS update, NIS Server is not configured 2019-01-17T11:03:13Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:13Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:13Z DEBUG Parsing update file '/usr/share/ipa/updates/55-pbacmemberof.update' 2019-01-17T11:03:13Z DEBUG New entry: cn=Update PBAC memberOf 1547722988,cn=memberof task,cn=tasks,cn=config 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=Update PBAC memberOf 1547722988,cn=memberof task,cn=tasks,cn=config 2019-01-17T11:03:13Z DEBUG add: 'top' to objectClass, current value [] 2019-01-17T11:03:13Z DEBUG add: updated value [u'top'] 2019-01-17T11:03:13Z DEBUG add: 'extensibleObject' to objectClass, current value [u'top'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'top', u'extensibleObject'] 2019-01-17T11:03:13Z DEBUG add: 'IPA PBAC memberOf 1547722988' to cn, current value [] 2019-01-17T11:03:13Z DEBUG add: updated value [u'IPA PBAC memberOf 1547722988'] 2019-01-17T11:03:13Z DEBUG add: 'cn=privileges,cn=pbac,dc=local' to basedn, current value [] 2019-01-17T11:03:13Z DEBUG add: updated value [u'cn=privileges,cn=pbac,dc=local'] 2019-01-17T11:03:13Z DEBUG add: '(objectclass=*)' to filter, current value [] 2019-01-17T11:03:13Z DEBUG add: updated value [u'(objectclass=*)'] 2019-01-17T11:03:13Z DEBUG add: '10' to ttl, current value [] 2019-01-17T11:03:13Z DEBUG add: updated value [u'10'] 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=Update PBAC memberOf 1547722988,cn=memberof task,cn=tasks,cn=config 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG filter: 2019-01-17T11:03:13Z DEBUG (objectclass=*) 2019-01-17T11:03:13Z DEBUG basedn: 2019-01-17T11:03:13Z DEBUG cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG IPA PBAC memberOf 1547722988 2019-01-17T11:03:13Z DEBUG ttl: 2019-01-17T11:03:13Z DEBUG 10 2019-01-17T11:03:13Z DEBUG New entry: cn=Update Role memberOf 1547722988,cn=memberof task,cn=tasks,cn=config 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=Update Role memberOf 1547722988,cn=memberof task,cn=tasks,cn=config 2019-01-17T11:03:13Z DEBUG add: 'top' to objectClass, current value [] 2019-01-17T11:03:13Z DEBUG add: updated value [u'top'] 2019-01-17T11:03:13Z DEBUG add: 'extensibleObject' to objectClass, current value [u'top'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'top', u'extensibleObject'] 2019-01-17T11:03:13Z DEBUG add: 'Update Role memberOf 1547722988' to cn, current value [] 2019-01-17T11:03:13Z DEBUG add: updated value [u'Update Role memberOf 1547722988'] 2019-01-17T11:03:13Z DEBUG add: 'cn=roles,cn=accounts,dc=local' to basedn, current value [] 2019-01-17T11:03:13Z DEBUG add: updated value [u'cn=roles,cn=accounts,dc=local'] 2019-01-17T11:03:13Z DEBUG add: '(objectclass=*)' to filter, current value [] 2019-01-17T11:03:13Z DEBUG add: updated value [u'(objectclass=*)'] 2019-01-17T11:03:13Z DEBUG add: '10' to ttl, current value [] 2019-01-17T11:03:13Z DEBUG add: updated value [u'10'] 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=Update Role memberOf 1547722988,cn=memberof task,cn=tasks,cn=config 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG filter: 2019-01-17T11:03:13Z DEBUG (objectclass=*) 2019-01-17T11:03:13Z DEBUG basedn: 2019-01-17T11:03:13Z DEBUG cn=roles,cn=accounts,dc=local 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG Update Role memberOf 1547722988 2019-01-17T11:03:13Z DEBUG ttl: 2019-01-17T11:03:13Z DEBUG 10 2019-01-17T11:03:13Z DEBUG Parsing update file '/usr/share/ipa/updates/59-trusts-sysacount.update' 2019-01-17T11:03:13Z DEBUG New entry: cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG GroupOfNames 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG adtrust agents 2019-01-17T11:03:13Z DEBUG add: 'nestedgroup' to objectClass, current value [u'GroupOfNames', u'top'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'GroupOfNames', u'top', u'nestedgroup'] 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG GroupOfNames 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG nestedgroup 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG adtrust agents 2019-01-17T11:03:13Z DEBUG Parsing update file '/usr/share/ipa/updates/60-trusts.update' 2019-01-17T11:03:13Z DEBUG New entry: cn=trust admins,cn=groups,cn=accounts,dc=local 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=trust admins,cn=groups,cn=accounts,dc=local 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG trust admins 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG groupofnames 2019-01-17T11:03:13Z DEBUG ipausergroup 2019-01-17T11:03:13Z DEBUG nestedgroup 2019-01-17T11:03:13Z DEBUG ipaobject 2019-01-17T11:03:13Z DEBUG member: 2019-01-17T11:03:13Z DEBUG uid=admin,cn=users,cn=accounts,dc=local 2019-01-17T11:03:13Z DEBUG ipaUniqueID: 2019-01-17T11:03:13Z DEBUG autogenerate 2019-01-17T11:03:13Z DEBUG nsAccountLock: 2019-01-17T11:03:13Z DEBUG FALSE 2019-01-17T11:03:13Z DEBUG description: 2019-01-17T11:03:13Z DEBUG Trusts administrators group 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=trust admins,cn=groups,cn=accounts,dc=local 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG trust admins 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG groupofnames 2019-01-17T11:03:13Z DEBUG ipausergroup 2019-01-17T11:03:13Z DEBUG nestedgroup 2019-01-17T11:03:13Z DEBUG ipaobject 2019-01-17T11:03:13Z DEBUG member: 2019-01-17T11:03:13Z DEBUG uid=admin,cn=users,cn=accounts,dc=local 2019-01-17T11:03:13Z DEBUG ipaUniqueID: 2019-01-17T11:03:13Z DEBUG autogenerate 2019-01-17T11:03:13Z DEBUG nsAccountLock: 2019-01-17T11:03:13Z DEBUG FALSE 2019-01-17T11:03:13Z DEBUG description: 2019-01-17T11:03:13Z DEBUG Trusts administrators group 2019-01-17T11:03:13Z DEBUG New entry: cn=ADTrust Agents,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=ADTrust Agents,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG groupofnames 2019-01-17T11:03:13Z DEBUG nestedgroup 2019-01-17T11:03:13Z DEBUG member: 2019-01-17T11:03:13Z DEBUG cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG ADTrust Agents 2019-01-17T11:03:13Z DEBUG description: 2019-01-17T11:03:13Z DEBUG System accounts able to access trust information 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=ADTrust Agents,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG groupofnames 2019-01-17T11:03:13Z DEBUG nestedgroup 2019-01-17T11:03:13Z DEBUG member: 2019-01-17T11:03:13Z DEBUG cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG ADTrust Agents 2019-01-17T11:03:13Z DEBUG description: 2019-01-17T11:03:13Z DEBUG System accounts able to access trust information 2019-01-17T11:03:13Z DEBUG New entry: cn=trusts,dc=local 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=trusts,dc=local 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG nsContainer 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG trusts 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=trusts,dc=local 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG nsContainer 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG trusts 2019-01-17T11:03:13Z DEBUG Updating existing entry: cn=trusts,dc=local 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=trusts,dc=local 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG nsContainer 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG trusts 2019-01-17T11:03:13Z DEBUG add: '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)' to aci, current value [] 2019-01-17T11:03:13Z DEBUG add: updated value [u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2019-01-17T11:03:13Z DEBUG add: '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)' to aci, current value [u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)'] 2019-01-17T11:03:13Z DEBUG add: '(target = "ldap:///cn=trusts,dc=local")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)' to aci, current value [u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)', u'(target = "ldap:///cn=trusts,dc=local")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)'] 2019-01-17T11:03:13Z DEBUG replace: updated value [u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)', u'(target = "ldap:///cn=trusts,dc=local")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)'] 2019-01-17T11:03:13Z DEBUG replace: (target = "ldap:///cn=trusts,dc=local")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=local";) not found, skipping 2019-01-17T11:03:13Z DEBUG add: '(target = "ldap:///cn=trusts,dc=local")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=local";)' to aci, current value [u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)', u'(target = "ldap:///cn=trusts,dc=local")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)', u'(target = "ldap:///cn=trusts,dc=local")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)', u'(target = "ldap:///cn=trusts,dc=local")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=local";)'] 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=trusts,dc=local 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG nsContainer 2019-01-17T11:03:13Z DEBUG aci: 2019-01-17T11:03:13Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2019-01-17T11:03:13Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";) 2019-01-17T11:03:13Z DEBUG (target = "ldap:///cn=trusts,dc=local")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";) 2019-01-17T11:03:13Z DEBUG (target = "ldap:///cn=trusts,dc=local")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG trusts 2019-01-17T11:03:13Z DEBUG [(2, u'aci', [u'(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', u'(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)', u'(target = "ldap:///cn=trusts,dc=local")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)', u'(target = "ldap:///cn=trusts,dc=local")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=local";)'])] 2019-01-17T11:03:13Z DEBUG Updated 1 2019-01-17T11:03:13Z DEBUG Done 2019-01-17T11:03:13Z DEBUG Updating existing entry: dc=local 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: dc=local 2019-01-17T11:03:13Z DEBUG info: 2019-01-17T11:03:13Z DEBUG IPA V2.0 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG domain 2019-01-17T11:03:13Z DEBUG pilotObject 2019-01-17T11:03:13Z DEBUG domainRelatedObject 2019-01-17T11:03:13Z DEBUG nisDomainObject 2019-01-17T11:03:13Z DEBUG associatedDomain: 2019-01-17T11:03:13Z DEBUG local 2019-01-17T11:03:13Z DEBUG dc: 2019-01-17T11:03:13Z DEBUG local 2019-01-17T11:03:13Z DEBUG nisDomain: 2019-01-17T11:03:13Z DEBUG local 2019-01-17T11:03:13Z DEBUG aci: 2019-01-17T11:03:13Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2019-01-17T11:03:13Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:13Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:13Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:13Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:13Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:13Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:13Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2019-01-17T11:03:13Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2019-01-17T11:03:13Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2019-01-17T11:03:13Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:13Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:13Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:13Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:13Z DEBUG add: '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local";)'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)'] 2019-01-17T11:03:13Z DEBUG remove: '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read NT passwords"; allow (read) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)' from aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)'] 2019-01-17T11:03:13Z DEBUG remove: '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read NT passwords"; allow (read) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)' not in aci 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: dc=local 2019-01-17T11:03:13Z DEBUG info: 2019-01-17T11:03:13Z DEBUG IPA V2.0 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG domain 2019-01-17T11:03:13Z DEBUG pilotObject 2019-01-17T11:03:13Z DEBUG domainRelatedObject 2019-01-17T11:03:13Z DEBUG nisDomainObject 2019-01-17T11:03:13Z DEBUG associatedDomain: 2019-01-17T11:03:13Z DEBUG local 2019-01-17T11:03:13Z DEBUG dc: 2019-01-17T11:03:13Z DEBUG local 2019-01-17T11:03:13Z DEBUG nisDomain: 2019-01-17T11:03:13Z DEBUG local 2019-01-17T11:03:13Z DEBUG aci: 2019-01-17T11:03:13Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2019-01-17T11:03:13Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:13Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:13Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:13Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:13Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:13Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:13Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2019-01-17T11:03:13Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2019-01-17T11:03:13Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2019-01-17T11:03:13Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:13Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:13Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:13Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";) 2019-01-17T11:03:13Z DEBUG [(0, u'aci', [u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)'])] 2019-01-17T11:03:13Z DEBUG Updated 1 2019-01-17T11:03:13Z DEBUG Done 2019-01-17T11:03:13Z DEBUG Updating existing entry: cn=ipaConfig,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=ipaConfig,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG ipaDefaultLoginShell: 2019-01-17T11:03:13Z DEBUG /bin/sh 2019-01-17T11:03:13Z DEBUG ipaCertificateSubjectBase: 2019-01-17T11:03:13Z DEBUG O=LOCAL 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG ipaConfig 2019-01-17T11:03:13Z DEBUG ipaSELinuxUserMapDefault: 2019-01-17T11:03:13Z DEBUG unconfined_u:s0-s0:c0.c1023 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG nsContainer 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG ipaGuiConfig 2019-01-17T11:03:13Z DEBUG ipaConfigObject 2019-01-17T11:03:13Z DEBUG ipaUserAuthTypeClass 2019-01-17T11:03:13Z DEBUG ipaNameResolutionData 2019-01-17T11:03:13Z DEBUG ipaHomesRootDir: 2019-01-17T11:03:13Z DEBUG /home 2019-01-17T11:03:13Z DEBUG ipaPwdExpAdvNotify: 2019-01-17T11:03:13Z DEBUG 4 2019-01-17T11:03:13Z DEBUG ipaUserObjectClasses: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG person 2019-01-17T11:03:13Z DEBUG organizationalperson 2019-01-17T11:03:13Z DEBUG inetorgperson 2019-01-17T11:03:13Z DEBUG inetuser 2019-01-17T11:03:13Z DEBUG posixaccount 2019-01-17T11:03:13Z DEBUG krbprincipalaux 2019-01-17T11:03:13Z DEBUG krbticketpolicyaux 2019-01-17T11:03:13Z DEBUG ipaobject 2019-01-17T11:03:13Z DEBUG ipasshuser 2019-01-17T11:03:13Z DEBUG ipaGroupSearchFields: 2019-01-17T11:03:13Z DEBUG cn,description 2019-01-17T11:03:13Z DEBUG ipaMigrationEnabled: 2019-01-17T11:03:13Z DEBUG FALSE 2019-01-17T11:03:13Z DEBUG ipaDefaultPrimaryGroup: 2019-01-17T11:03:13Z DEBUG ipausers 2019-01-17T11:03:13Z DEBUG ipaSearchTimeLimit: 2019-01-17T11:03:13Z DEBUG 2 2019-01-17T11:03:13Z DEBUG ipaGroupObjectClasses: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG groupofnames 2019-01-17T11:03:13Z DEBUG nestedgroup 2019-01-17T11:03:13Z DEBUG ipausergroup 2019-01-17T11:03:13Z DEBUG ipaobject 2019-01-17T11:03:13Z DEBUG ipaDefaultEmailDomain: 2019-01-17T11:03:13Z DEBUG local 2019-01-17T11:03:13Z DEBUG ipaSearchRecordsLimit: 2019-01-17T11:03:13Z DEBUG 100 2019-01-17T11:03:13Z DEBUG ipaSELinuxUserMapOrder: 2019-01-17T11:03:13Z DEBUG guest_u:s0$xguest_u:s0$user_u:s0$staff_u:s0-s0:c0.c1023$unconfined_u:s0-s0:c0.c1023 2019-01-17T11:03:13Z DEBUG ipaConfigString: 2019-01-17T11:03:13Z DEBUG AllowNThash 2019-01-17T11:03:13Z DEBUG KDC:Disable Last Success 2019-01-17T11:03:13Z DEBUG ipaMaxUsernameLength: 2019-01-17T11:03:13Z DEBUG 32 2019-01-17T11:03:13Z DEBUG ipaUserSearchFields: 2019-01-17T11:03:13Z DEBUG uid,givenname,sn,telephonenumber,ou,title 2019-01-17T11:03:13Z DEBUG addifnew: 'MS-PAC' to ipaKrbAuthzData, current value [] 2019-01-17T11:03:13Z DEBUG addifnew: set ipaKrbAuthzData to [u'MS-PAC'] 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=ipaConfig,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG ipaDefaultLoginShell: 2019-01-17T11:03:13Z DEBUG /bin/sh 2019-01-17T11:03:13Z DEBUG ipaCertificateSubjectBase: 2019-01-17T11:03:13Z DEBUG O=LOCAL 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG ipaConfig 2019-01-17T11:03:13Z DEBUG ipaSELinuxUserMapDefault: 2019-01-17T11:03:13Z DEBUG unconfined_u:s0-s0:c0.c1023 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG nsContainer 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG ipaGuiConfig 2019-01-17T11:03:13Z DEBUG ipaConfigObject 2019-01-17T11:03:13Z DEBUG ipaUserAuthTypeClass 2019-01-17T11:03:13Z DEBUG ipaNameResolutionData 2019-01-17T11:03:13Z DEBUG ipaKrbAuthzData: 2019-01-17T11:03:13Z DEBUG MS-PAC 2019-01-17T11:03:13Z DEBUG ipaHomesRootDir: 2019-01-17T11:03:13Z DEBUG /home 2019-01-17T11:03:13Z DEBUG ipaPwdExpAdvNotify: 2019-01-17T11:03:13Z DEBUG 4 2019-01-17T11:03:13Z DEBUG ipaUserObjectClasses: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG person 2019-01-17T11:03:13Z DEBUG organizationalperson 2019-01-17T11:03:13Z DEBUG inetorgperson 2019-01-17T11:03:13Z DEBUG inetuser 2019-01-17T11:03:13Z DEBUG posixaccount 2019-01-17T11:03:13Z DEBUG krbprincipalaux 2019-01-17T11:03:13Z DEBUG krbticketpolicyaux 2019-01-17T11:03:13Z DEBUG ipaobject 2019-01-17T11:03:13Z DEBUG ipasshuser 2019-01-17T11:03:13Z DEBUG ipaGroupSearchFields: 2019-01-17T11:03:13Z DEBUG cn,description 2019-01-17T11:03:13Z DEBUG ipaMigrationEnabled: 2019-01-17T11:03:13Z DEBUG FALSE 2019-01-17T11:03:13Z DEBUG ipaDefaultPrimaryGroup: 2019-01-17T11:03:13Z DEBUG ipausers 2019-01-17T11:03:13Z DEBUG ipaSearchTimeLimit: 2019-01-17T11:03:13Z DEBUG 2 2019-01-17T11:03:13Z DEBUG ipaGroupObjectClasses: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG groupofnames 2019-01-17T11:03:13Z DEBUG nestedgroup 2019-01-17T11:03:13Z DEBUG ipausergroup 2019-01-17T11:03:13Z DEBUG ipaobject 2019-01-17T11:03:13Z DEBUG ipaDefaultEmailDomain: 2019-01-17T11:03:13Z DEBUG local 2019-01-17T11:03:13Z DEBUG ipaSearchRecordsLimit: 2019-01-17T11:03:13Z DEBUG 100 2019-01-17T11:03:13Z DEBUG ipaSELinuxUserMapOrder: 2019-01-17T11:03:13Z DEBUG guest_u:s0$xguest_u:s0$user_u:s0$staff_u:s0-s0:c0.c1023$unconfined_u:s0-s0:c0.c1023 2019-01-17T11:03:13Z DEBUG ipaConfigString: 2019-01-17T11:03:13Z DEBUG AllowNThash 2019-01-17T11:03:13Z DEBUG KDC:Disable Last Success 2019-01-17T11:03:13Z DEBUG ipaMaxUsernameLength: 2019-01-17T11:03:13Z DEBUG 32 2019-01-17T11:03:13Z DEBUG ipaUserSearchFields: 2019-01-17T11:03:13Z DEBUG uid,givenname,sn,telephonenumber,ou,title 2019-01-17T11:03:13Z DEBUG [(2, u'ipaKrbAuthzData', [u'MS-PAC'])] 2019-01-17T11:03:13Z DEBUG Updated 1 2019-01-17T11:03:13Z DEBUG Done 2019-01-17T11:03:13Z DEBUG Parsing update file '/usr/share/ipa/updates/61-trusts-s4u2proxy.update' 2019-01-17T11:03:13Z DEBUG Updating existing entry: cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG groupOfPrincipals 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG ipa-cifs-delegation-targets 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG groupOfPrincipals 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG ipa-cifs-delegation-targets 2019-01-17T11:03:13Z DEBUG [] 2019-01-17T11:03:13Z DEBUG Updated 0 2019-01-17T11:03:13Z DEBUG Done 2019-01-17T11:03:13Z DEBUG Updating existing entry: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG ipaKrb5DelegationACL 2019-01-17T11:03:13Z DEBUG groupOfPrincipals 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG memberPrincipal: 2019-01-17T11:03:13Z DEBUG HTTP/centos75.local@LOCAL 2019-01-17T11:03:13Z DEBUG ipaAllowedTarget: 2019-01-17T11:03:13Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG ipa-http-delegation 2019-01-17T11:03:13Z DEBUG add: 'cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=local' to ipaAllowedTarget, current value [u'cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=local', u'cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=local'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=local', u'cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=local'] 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG ipaKrb5DelegationACL 2019-01-17T11:03:13Z DEBUG groupOfPrincipals 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG memberPrincipal: 2019-01-17T11:03:13Z DEBUG HTTP/centos75.local@LOCAL 2019-01-17T11:03:13Z DEBUG ipaAllowedTarget: 2019-01-17T11:03:13Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG ipa-http-delegation 2019-01-17T11:03:13Z DEBUG [] 2019-01-17T11:03:13Z DEBUG Updated 0 2019-01-17T11:03:13Z DEBUG Done 2019-01-17T11:03:13Z DEBUG Parsing update file '/usr/share/ipa/updates/62-ranges.update' 2019-01-17T11:03:13Z DEBUG Updating existing entry: cn=ranges,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=ranges,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG nsContainer 2019-01-17T11:03:13Z DEBUG aci: 2019-01-17T11:03:13Z DEBUG (target = "ldap:///cn=*,cn=ranges,cn=etc,dc=local")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@LOCAL,cn=services,cn=accounts,dc=local" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";) 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG ranges 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=ranges,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG nsContainer 2019-01-17T11:03:13Z DEBUG aci: 2019-01-17T11:03:13Z DEBUG (target = "ldap:///cn=*,cn=ranges,cn=etc,dc=local")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@LOCAL,cn=services,cn=accounts,dc=local" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";) 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG ranges 2019-01-17T11:03:13Z DEBUG [] 2019-01-17T11:03:13Z DEBUG Updated 0 2019-01-17T11:03:13Z DEBUG Done 2019-01-17T11:03:13Z DEBUG Updating existing entry: cn=IPA Range-Check,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=IPA Range-Check,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:13Z DEBUG IPA ID range check plugin 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG IPA Range-Check 2019-01-17T11:03:13Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:13Z DEBUG FreeIPA/1.0 2019-01-17T11:03:13Z DEBUG nsslapd-basedn: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:13Z DEBUG Check if newly added or modified ID ranges do not overlap with existing ones 2019-01-17T11:03:13Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:13Z DEBUG on 2019-01-17T11:03:13Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:13Z DEBUG libipa_range_check 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG nsSlapdPlugin 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:13Z DEBUG database 2019-01-17T11:03:13Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:13Z DEBUG FreeIPA project 2019-01-17T11:03:13Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:13Z DEBUG preoperation 2019-01-17T11:03:13Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:13Z DEBUG ipa_range_check_init 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=IPA Range-Check,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:13Z DEBUG IPA ID range check plugin 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG IPA Range-Check 2019-01-17T11:03:13Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:13Z DEBUG FreeIPA/1.0 2019-01-17T11:03:13Z DEBUG nsslapd-basedn: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:13Z DEBUG Check if newly added or modified ID ranges do not overlap with existing ones 2019-01-17T11:03:13Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:13Z DEBUG on 2019-01-17T11:03:13Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:13Z DEBUG libipa_range_check 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG nsSlapdPlugin 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG nsslapd-plugin-depends-on-type: 2019-01-17T11:03:13Z DEBUG database 2019-01-17T11:03:13Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:13Z DEBUG FreeIPA project 2019-01-17T11:03:13Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:13Z DEBUG preoperation 2019-01-17T11:03:13Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:13Z DEBUG ipa_range_check_init 2019-01-17T11:03:13Z DEBUG [] 2019-01-17T11:03:13Z DEBUG Updated 0 2019-01-17T11:03:13Z DEBUG Done 2019-01-17T11:03:13Z DEBUG Updating existing entry: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG dnaScope: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG dnaThreshold: 2019-01-17T11:03:13Z DEBUG 500 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG Posix IDs 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG aci: 2019-01-17T11:03:13Z DEBUG (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:13Z DEBUG dnaMagicRegen: 2019-01-17T11:03:13Z DEBUG -1 2019-01-17T11:03:13Z DEBUG dnaNextValue: 2019-01-17T11:03:13Z DEBUG 353600000 2019-01-17T11:03:13Z DEBUG dnaExcludeScope: 2019-01-17T11:03:13Z DEBUG cn=provisioning,dc=local 2019-01-17T11:03:13Z DEBUG dnaFilter: 2019-01-17T11:03:13Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2019-01-17T11:03:13Z DEBUG dnaType: 2019-01-17T11:03:13Z DEBUG uidNumber 2019-01-17T11:03:13Z DEBUG gidNumber 2019-01-17T11:03:13Z DEBUG dnaMaxValue: 2019-01-17T11:03:13Z DEBUG 353799999 2019-01-17T11:03:13Z DEBUG dnaSharedCfgDN: 2019-01-17T11:03:13Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG replace: (|(objectclass=posixAccount)(objectClass=posixGroup)) not found, skipping 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG dnaScope: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG dnaThreshold: 2019-01-17T11:03:13Z DEBUG 500 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG Posix IDs 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG aci: 2019-01-17T11:03:13Z DEBUG (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:13Z DEBUG dnaMagicRegen: 2019-01-17T11:03:13Z DEBUG -1 2019-01-17T11:03:13Z DEBUG dnaNextValue: 2019-01-17T11:03:13Z DEBUG 353600000 2019-01-17T11:03:13Z DEBUG dnaExcludeScope: 2019-01-17T11:03:13Z DEBUG cn=provisioning,dc=local 2019-01-17T11:03:13Z DEBUG dnaFilter: 2019-01-17T11:03:13Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2019-01-17T11:03:13Z DEBUG dnaType: 2019-01-17T11:03:13Z DEBUG uidNumber 2019-01-17T11:03:13Z DEBUG gidNumber 2019-01-17T11:03:13Z DEBUG dnaMaxValue: 2019-01-17T11:03:13Z DEBUG 353799999 2019-01-17T11:03:13Z DEBUG dnaSharedCfgDN: 2019-01-17T11:03:13Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG [] 2019-01-17T11:03:13Z DEBUG Updated 0 2019-01-17T11:03:13Z DEBUG Done 2019-01-17T11:03:13Z DEBUG Parsing update file '/usr/share/ipa/updates/71-idviews-sasl-mapping.update' 2019-01-17T11:03:13Z DEBUG Updating existing entry: cn=ID Overridden Principal,cn=mapping,cn=sasl,cn=config 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=ID Overridden Principal,cn=mapping,cn=sasl,cn=config 2019-01-17T11:03:13Z DEBUG nsSaslMapPriority: 2019-01-17T11:03:13Z DEBUG 20 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG ID Overridden Principal 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG nsSaslMapping 2019-01-17T11:03:13Z DEBUG nsSaslMapRegexString: 2019-01-17T11:03:13Z DEBUG \(.*\)@\(.*\) 2019-01-17T11:03:13Z DEBUG nsSaslMapBaseDNTemplate: 2019-01-17T11:03:13Z DEBUG cn=default trust view,cn=views,cn=accounts,dc=local 2019-01-17T11:03:13Z DEBUG nsSaslMapFilterTemplate: 2019-01-17T11:03:13Z DEBUG (&(ipaoriginaluid=\1@\2)(objectclass=ipaUserOverride)) 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=ID Overridden Principal,cn=mapping,cn=sasl,cn=config 2019-01-17T11:03:13Z DEBUG nsSaslMapPriority: 2019-01-17T11:03:13Z DEBUG 20 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG ID Overridden Principal 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG nsSaslMapping 2019-01-17T11:03:13Z DEBUG nsSaslMapRegexString: 2019-01-17T11:03:13Z DEBUG \(.*\)@\(.*\) 2019-01-17T11:03:13Z DEBUG nsSaslMapBaseDNTemplate: 2019-01-17T11:03:13Z DEBUG cn=default trust view,cn=views,cn=accounts,dc=local 2019-01-17T11:03:13Z DEBUG nsSaslMapFilterTemplate: 2019-01-17T11:03:13Z DEBUG (&(ipaoriginaluid=\1@\2)(objectclass=ipaUserOverride)) 2019-01-17T11:03:13Z DEBUG [] 2019-01-17T11:03:13Z DEBUG Updated 0 2019-01-17T11:03:13Z DEBUG Done 2019-01-17T11:03:13Z DEBUG Parsing update file '/usr/share/ipa/updates/71-idviews.update' 2019-01-17T11:03:13Z DEBUG New entry: cn=views,cn=accounts,dc=local 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=views,cn=accounts,dc=local 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG nsContainer 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG views 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=views,cn=accounts,dc=local 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG nsContainer 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG views 2019-01-17T11:03:13Z DEBUG Parsing update file '/usr/share/ipa/updates/72-domainlevels.update' 2019-01-17T11:03:13Z DEBUG Updating existing entry: cn=Domain Level,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=Domain Level,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG nsContainer 2019-01-17T11:03:13Z DEBUG ipaDomainLevelConfig 2019-01-17T11:03:13Z DEBUG ipaConfigObject 2019-01-17T11:03:13Z DEBUG ipaDomainLevel: 2019-01-17T11:03:13Z DEBUG 1 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG Domain Level 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=Domain Level,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG nsContainer 2019-01-17T11:03:13Z DEBUG ipaDomainLevelConfig 2019-01-17T11:03:13Z DEBUG ipaConfigObject 2019-01-17T11:03:13Z DEBUG ipaDomainLevel: 2019-01-17T11:03:13Z DEBUG 1 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG Domain Level 2019-01-17T11:03:13Z DEBUG [] 2019-01-17T11:03:13Z DEBUG Updated 0 2019-01-17T11:03:13Z DEBUG Done 2019-01-17T11:03:13Z DEBUG Updating existing entry: cn=centos75.local,cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=centos75.local,cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG nsContainer 2019-01-17T11:03:13Z DEBUG ipaReplTopoManagedServer 2019-01-17T11:03:13Z DEBUG ipaConfigObject 2019-01-17T11:03:13Z DEBUG ipaSupportedDomainLevelConfig 2019-01-17T11:03:13Z DEBUG ipaMaxDomainLevel: 2019-01-17T11:03:13Z DEBUG 1 2019-01-17T11:03:13Z DEBUG ipaMinDomainLevel: 2019-01-17T11:03:13Z DEBUG 0 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG centos75.local 2019-01-17T11:03:13Z DEBUG ipaReplTopoManagedSuffix: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG add: 'ipaConfigObject' to objectClass, current value [u'top', u'nsContainer', u'ipaReplTopoManagedServer', u'ipaConfigObject', u'ipaSupportedDomainLevelConfig'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'top', u'nsContainer', u'ipaReplTopoManagedServer', u'ipaSupportedDomainLevelConfig', u'ipaConfigObject'] 2019-01-17T11:03:13Z DEBUG add: 'ipaSupportedDomainLevelConfig' to objectClass, current value [u'top', u'nsContainer', u'ipaReplTopoManagedServer', u'ipaSupportedDomainLevelConfig', u'ipaConfigObject'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'top', u'nsContainer', u'ipaReplTopoManagedServer', u'ipaConfigObject', u'ipaSupportedDomainLevelConfig'] 2019-01-17T11:03:13Z DEBUG only: set ipaMinDomainLevel to '0', current value [u'0'] 2019-01-17T11:03:13Z DEBUG only: updated value [u'0'] 2019-01-17T11:03:13Z DEBUG only: set ipaMaxDomainLevel to '1', current value [u'1'] 2019-01-17T11:03:13Z DEBUG only: updated value [u'1'] 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=centos75.local,cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG nsContainer 2019-01-17T11:03:13Z DEBUG ipaReplTopoManagedServer 2019-01-17T11:03:13Z DEBUG ipaConfigObject 2019-01-17T11:03:13Z DEBUG ipaSupportedDomainLevelConfig 2019-01-17T11:03:13Z DEBUG ipaMaxDomainLevel: 2019-01-17T11:03:13Z DEBUG 1 2019-01-17T11:03:13Z DEBUG ipaMinDomainLevel: 2019-01-17T11:03:13Z DEBUG 0 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG centos75.local 2019-01-17T11:03:13Z DEBUG ipaReplTopoManagedSuffix: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG [] 2019-01-17T11:03:13Z DEBUG Updated 0 2019-01-17T11:03:13Z DEBUG Done 2019-01-17T11:03:13Z DEBUG Parsing update file '/usr/share/ipa/updates/73-certmap.update' 2019-01-17T11:03:13Z DEBUG New entry: cn=certmap,dc=local 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=certmap,dc=local 2019-01-17T11:03:13Z DEBUG objectclass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG nsContainer 2019-01-17T11:03:13Z DEBUG ipaCertMapConfigObject 2019-01-17T11:03:13Z DEBUG ipaCertMapPromptUsername: 2019-01-17T11:03:13Z DEBUG FALSE 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG certmap 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=certmap,dc=local 2019-01-17T11:03:13Z DEBUG objectclass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG nsContainer 2019-01-17T11:03:13Z DEBUG ipaCertMapConfigObject 2019-01-17T11:03:13Z DEBUG ipaCertMapPromptUsername: 2019-01-17T11:03:13Z DEBUG FALSE 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG certmap 2019-01-17T11:03:13Z DEBUG New entry: cn=certmaprules,cn=certmap,dc=local 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=certmaprules,cn=certmap,dc=local 2019-01-17T11:03:13Z DEBUG objectclass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG nsContainer 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG certmaprules 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=certmaprules,cn=certmap,dc=local 2019-01-17T11:03:13Z DEBUG objectclass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG nsContainer 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG certmaprules 2019-01-17T11:03:13Z DEBUG New entry: cn=Certificate Identity Mapping Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=Certificate Identity Mapping Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG groupofnames 2019-01-17T11:03:13Z DEBUG nestedgroup 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG Certificate Identity Mapping Administrators 2019-01-17T11:03:13Z DEBUG description: 2019-01-17T11:03:13Z DEBUG Certificate Identity Mapping Administrators 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=Certificate Identity Mapping Administrators,cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG groupofnames 2019-01-17T11:03:13Z DEBUG nestedgroup 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG Certificate Identity Mapping Administrators 2019-01-17T11:03:13Z DEBUG description: 2019-01-17T11:03:13Z DEBUG Certificate Identity Mapping Administrators 2019-01-17T11:03:13Z DEBUG Updating existing entry: dc=local 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: dc=local 2019-01-17T11:03:13Z DEBUG info: 2019-01-17T11:03:13Z DEBUG IPA V2.0 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG domain 2019-01-17T11:03:13Z DEBUG pilotObject 2019-01-17T11:03:13Z DEBUG domainRelatedObject 2019-01-17T11:03:13Z DEBUG nisDomainObject 2019-01-17T11:03:13Z DEBUG associatedDomain: 2019-01-17T11:03:13Z DEBUG local 2019-01-17T11:03:13Z DEBUG dc: 2019-01-17T11:03:13Z DEBUG local 2019-01-17T11:03:13Z DEBUG nisDomain: 2019-01-17T11:03:13Z DEBUG local 2019-01-17T11:03:13Z DEBUG aci: 2019-01-17T11:03:13Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2019-01-17T11:03:13Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:13Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:13Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:13Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:13Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:13Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:13Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2019-01-17T11:03:13Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2019-01-17T11:03:13Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2019-01-17T11:03:13Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:13Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:13Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:13Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";) 2019-01-17T11:03:13Z DEBUG add: '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)' to aci, current value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', u'(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', u'(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', u'(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', u'(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', u'(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', u'(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', u'(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";)', u'(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local";)', u'(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";)', u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)'] 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: dc=local 2019-01-17T11:03:13Z DEBUG info: 2019-01-17T11:03:13Z DEBUG IPA V2.0 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG domain 2019-01-17T11:03:13Z DEBUG pilotObject 2019-01-17T11:03:13Z DEBUG domainRelatedObject 2019-01-17T11:03:13Z DEBUG nisDomainObject 2019-01-17T11:03:13Z DEBUG associatedDomain: 2019-01-17T11:03:13Z DEBUG local 2019-01-17T11:03:13Z DEBUG dc: 2019-01-17T11:03:13Z DEBUG local 2019-01-17T11:03:13Z DEBUG nisDomain: 2019-01-17T11:03:13Z DEBUG local 2019-01-17T11:03:13Z DEBUG aci: 2019-01-17T11:03:13Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=local" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2019-01-17T11:03:13Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:13Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:13Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:13Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:13Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:13Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2019-01-17T11:03:13Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2019-01-17T11:03:13Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2019-01-17T11:03:13Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=local")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2019-01-17T11:03:13Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:13Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:13Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=local")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2019-01-17T11:03:13Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=local" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=local" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=local";) 2019-01-17T11:03:13Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2019-01-17T11:03:13Z DEBUG [(0, u'aci', [u'(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)'])] 2019-01-17T11:03:13Z DEBUG Updated 1 2019-01-17T11:03:13Z DEBUG Done 2019-01-17T11:03:13Z DEBUG Parsing update file '/usr/share/ipa/updates/73-custodia.update' 2019-01-17T11:03:13Z DEBUG Updating existing entry: cn=custodia,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=custodia,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG nsContainer 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG custodia 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=custodia,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG nsContainer 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG custodia 2019-01-17T11:03:13Z DEBUG [] 2019-01-17T11:03:13Z DEBUG Updated 0 2019-01-17T11:03:13Z DEBUG Done 2019-01-17T11:03:13Z DEBUG Updating existing entry: cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG nsContainer 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG dogtag 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG nsContainer 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG dogtag 2019-01-17T11:03:13Z DEBUG [] 2019-01-17T11:03:13Z DEBUG Updated 0 2019-01-17T11:03:13Z DEBUG Done 2019-01-17T11:03:13Z DEBUG Parsing update file '/usr/share/ipa/updates/73-winsync.update' 2019-01-17T11:03:13Z DEBUG New entry: uid=passsync,cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: uid=passsync,cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG addifexist: 'inetUser' to objectClass, current value [] 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: uid=passsync,cn=sysaccounts,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG Parsing update file '/usr/share/ipa/updates/80-schema_compat.update' 2019-01-17T11:03:13Z DEBUG Updating existing entry: cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:03:13Z DEBUG on 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG Schema Compatibility 2019-01-17T11:03:13Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:13Z DEBUG none 2019-01-17T11:03:13Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:13Z DEBUG none 2019-01-17T11:03:13Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:13Z DEBUG off 2019-01-17T11:03:13Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:13Z DEBUG /usr/lib64/dirsrv/plugins/schemacompat-plugin.so 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG nsSlapdPlugin 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:13Z DEBUG none 2019-01-17T11:03:13Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:13Z DEBUG schema_compat_plugin_init 2019-01-17T11:03:13Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:03:13Z DEBUG 40 2019-01-17T11:03:13Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:13Z DEBUG object 2019-01-17T11:03:13Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:13Z DEBUG none 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:03:13Z DEBUG on 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG Schema Compatibility 2019-01-17T11:03:13Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:13Z DEBUG none 2019-01-17T11:03:13Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:13Z DEBUG none 2019-01-17T11:03:13Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:13Z DEBUG off 2019-01-17T11:03:13Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:13Z DEBUG /usr/lib64/dirsrv/plugins/schemacompat-plugin.so 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG nsSlapdPlugin 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:13Z DEBUG none 2019-01-17T11:03:13Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:13Z DEBUG schema_compat_plugin_init 2019-01-17T11:03:13Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:03:13Z DEBUG 40 2019-01-17T11:03:13Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:13Z DEBUG object 2019-01-17T11:03:13Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:13Z DEBUG none 2019-01-17T11:03:13Z DEBUG [] 2019-01-17T11:03:13Z DEBUG Updated 0 2019-01-17T11:03:13Z DEBUG Done 2019-01-17T11:03:13Z DEBUG Updating existing entry: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:03:13Z DEBUG objectclass=posixAccount 2019-01-17T11:03:13Z DEBUG gecos=%{cn} 2019-01-17T11:03:13Z DEBUG cn=%{cn} 2019-01-17T11:03:13Z DEBUG uidNumber=%{uidNumber} 2019-01-17T11:03:13Z DEBUG gidNumber=%{gidNumber} 2019-01-17T11:03:13Z DEBUG loginShell=%{loginShell} 2019-01-17T11:03:13Z DEBUG homeDirectory=%{homeDirectory} 2019-01-17T11:03:13Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:03:13Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","") 2019-01-17T11:03:13Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2019-01-17T11:03:13Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:03:13Z DEBUG uid=%{uid} 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG users 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG schema-compat-container-rdn: 2019-01-17T11:03:13Z DEBUG cn=users 2019-01-17T11:03:13Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:03:13Z DEBUG uid=%first("%{uid}") 2019-01-17T11:03:13Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:03:13Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-search-filter: 2019-01-17T11:03:13Z DEBUG objectclass=posixAccount 2019-01-17T11:03:13Z DEBUG schema-compat-search-base: 2019-01-17T11:03:13Z DEBUG cn=users, cn=accounts, dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-container-group: 2019-01-17T11:03:13Z DEBUG cn=compat, dc=local 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:03:13Z DEBUG objectclass=posixAccount 2019-01-17T11:03:13Z DEBUG gecos=%{cn} 2019-01-17T11:03:13Z DEBUG cn=%{cn} 2019-01-17T11:03:13Z DEBUG uidNumber=%{uidNumber} 2019-01-17T11:03:13Z DEBUG gidNumber=%{gidNumber} 2019-01-17T11:03:13Z DEBUG loginShell=%{loginShell} 2019-01-17T11:03:13Z DEBUG homeDirectory=%{homeDirectory} 2019-01-17T11:03:13Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:03:13Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","") 2019-01-17T11:03:13Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2019-01-17T11:03:13Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:03:13Z DEBUG uid=%{uid} 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG users 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG schema-compat-container-rdn: 2019-01-17T11:03:13Z DEBUG cn=users 2019-01-17T11:03:13Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:03:13Z DEBUG uid=%first("%{uid}") 2019-01-17T11:03:13Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:03:13Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-search-filter: 2019-01-17T11:03:13Z DEBUG objectclass=posixAccount 2019-01-17T11:03:13Z DEBUG schema-compat-search-base: 2019-01-17T11:03:13Z DEBUG cn=users, cn=accounts, dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-container-group: 2019-01-17T11:03:13Z DEBUG cn=compat, dc=local 2019-01-17T11:03:13Z DEBUG [] 2019-01-17T11:03:13Z DEBUG Updated 0 2019-01-17T11:03:13Z DEBUG Done 2019-01-17T11:03:13Z DEBUG Updating existing entry: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:03:13Z DEBUG objectclass=posixGroup 2019-01-17T11:03:13Z DEBUG gidNumber=%{gidNumber} 2019-01-17T11:03:13Z DEBUG memberUid=%{memberUid} 2019-01-17T11:03:13Z DEBUG memberUid=%deref_r("member","uid") 2019-01-17T11:03:13Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:03:13Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","") 2019-01-17T11:03:13Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2019-01-17T11:03:13Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:03:13Z DEBUG ipaexternalmember=%deref_r("member","ipaexternalmember") 2019-01-17T11:03:13Z DEBUG objectclass=ipaexternalgroup 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG groups 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG schema-compat-container-rdn: 2019-01-17T11:03:13Z DEBUG cn=groups 2019-01-17T11:03:13Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:03:13Z DEBUG cn=%{cn} 2019-01-17T11:03:13Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:03:13Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-search-filter: 2019-01-17T11:03:13Z DEBUG objectclass=posixGroup 2019-01-17T11:03:13Z DEBUG schema-compat-search-base: 2019-01-17T11:03:13Z DEBUG cn=groups, cn=accounts, dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-container-group: 2019-01-17T11:03:13Z DEBUG cn=compat, dc=local 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:03:13Z DEBUG objectclass=posixGroup 2019-01-17T11:03:13Z DEBUG gidNumber=%{gidNumber} 2019-01-17T11:03:13Z DEBUG memberUid=%{memberUid} 2019-01-17T11:03:13Z DEBUG memberUid=%deref_r("member","uid") 2019-01-17T11:03:13Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:03:13Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","") 2019-01-17T11:03:13Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2019-01-17T11:03:13Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:03:13Z DEBUG ipaexternalmember=%deref_r("member","ipaexternalmember") 2019-01-17T11:03:13Z DEBUG objectclass=ipaexternalgroup 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG groups 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG schema-compat-container-rdn: 2019-01-17T11:03:13Z DEBUG cn=groups 2019-01-17T11:03:13Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:03:13Z DEBUG cn=%{cn} 2019-01-17T11:03:13Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:03:13Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-search-filter: 2019-01-17T11:03:13Z DEBUG objectclass=posixGroup 2019-01-17T11:03:13Z DEBUG schema-compat-search-base: 2019-01-17T11:03:13Z DEBUG cn=groups, cn=accounts, dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-container-group: 2019-01-17T11:03:13Z DEBUG cn=compat, dc=local 2019-01-17T11:03:13Z DEBUG [] 2019-01-17T11:03:13Z DEBUG Updated 0 2019-01-17T11:03:13Z DEBUG Done 2019-01-17T11:03:13Z DEBUG Updating existing entry: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:03:13Z DEBUG objectclass=nisNetgroup 2019-01-17T11:03:13Z DEBUG memberNisNetgroup=%deref_r("member","cn") 2019-01-17T11:03:13Z DEBUG nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","%ifeq(\"hostCategory\",\"all\",\"\",\"-\")",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","%ifeq(\"userCategory\",\"all\",\"\",\"-\")"),%{nisDomainName:-}) 2019-01-17T11:03:13Z DEBUG schema-compat-check-access: 2019-01-17T11:03:13Z DEBUG yes 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG ng 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG schema-compat-container-rdn: 2019-01-17T11:03:13Z DEBUG cn=ng 2019-01-17T11:03:13Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-search-filter: 2019-01-17T11:03:13Z DEBUG (objectclass=ipaNisNetgroup) 2019-01-17T11:03:13Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:03:13Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:03:13Z DEBUG cn=%{cn} 2019-01-17T11:03:13Z DEBUG schema-compat-search-base: 2019-01-17T11:03:13Z DEBUG cn=ng, cn=alt, dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-container-group: 2019-01-17T11:03:13Z DEBUG cn=compat, dc=local 2019-01-17T11:03:13Z DEBUG add: 'top' to objectClass, current value [u'top', u'extensibleObject'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'extensibleObject', u'top'] 2019-01-17T11:03:13Z DEBUG add: 'extensibleObject' to objectClass, current value [u'extensibleObject', u'top'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'top', u'extensibleObject'] 2019-01-17T11:03:13Z DEBUG add: 'ng' to cn, current value [u'ng'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'ng'] 2019-01-17T11:03:13Z DEBUG add: 'cn=compat, dc=local' to schema-compat-container-group, current value [u'cn=compat, dc=local'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'cn=compat, dc=local'] 2019-01-17T11:03:13Z DEBUG add: 'cn=ng' to schema-compat-container-rdn, current value [u'cn=ng'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'cn=ng'] 2019-01-17T11:03:13Z DEBUG add: 'yes' to schema-compat-check-access, current value [u'yes'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'yes'] 2019-01-17T11:03:13Z DEBUG add: 'cn=ng, cn=alt, dc=local' to schema-compat-search-base, current value [u'cn=ng, cn=alt, dc=local'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'cn=ng, cn=alt, dc=local'] 2019-01-17T11:03:13Z DEBUG add: '(objectclass=ipaNisNetgroup)' to schema-compat-search-filter, current value [u'(objectclass=ipaNisNetgroup)'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'(objectclass=ipaNisNetgroup)'] 2019-01-17T11:03:13Z DEBUG add: 'cn=%{cn}' to schema-compat-entry-rdn, current value [u'cn=%{cn}'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'cn=%{cn}'] 2019-01-17T11:03:13Z DEBUG add: 'objectclass=nisNetgroup' to schema-compat-entry-attribute, current value [u'objectclass=nisNetgroup', u'memberNisNetgroup=%deref_r("member","cn")', u'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"-\\")",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"-\\")"),%{nisDomainName:-})'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'memberNisNetgroup=%deref_r("member","cn")', u'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"-\\")",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"-\\")"),%{nisDomainName:-})', u'objectclass=nisNetgroup'] 2019-01-17T11:03:13Z DEBUG add: 'memberNisNetgroup=%deref_r("member","cn")' to schema-compat-entry-attribute, current value [u'memberNisNetgroup=%deref_r("member","cn")', u'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"-\\")",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"-\\")"),%{nisDomainName:-})', u'objectclass=nisNetgroup'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"-\\")",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"-\\")"),%{nisDomainName:-})', u'objectclass=nisNetgroup', u'memberNisNetgroup=%deref_r("member","cn")'] 2019-01-17T11:03:13Z DEBUG add: 'nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","-",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","-"),%{nisDomainName:-})' to schema-compat-entry-attribute, current value [u'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"-\\")",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"-\\")"),%{nisDomainName:-})', u'objectclass=nisNetgroup', u'memberNisNetgroup=%deref_r("member","cn")'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"-\\")",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"-\\")"),%{nisDomainName:-})', u'objectclass=nisNetgroup', u'memberNisNetgroup=%deref_r("member","cn")', u'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","-",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","-"),%{nisDomainName:-})'] 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:03:13Z DEBUG nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","%ifeq(\"hostCategory\",\"all\",\"\",\"-\")",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","%ifeq(\"userCategory\",\"all\",\"\",\"-\")"),%{nisDomainName:-}) 2019-01-17T11:03:13Z DEBUG objectclass=nisNetgroup 2019-01-17T11:03:13Z DEBUG memberNisNetgroup=%deref_r("member","cn") 2019-01-17T11:03:13Z DEBUG nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","-",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","-"),%{nisDomainName:-}) 2019-01-17T11:03:13Z DEBUG schema-compat-check-access: 2019-01-17T11:03:13Z DEBUG yes 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG ng 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG schema-compat-container-rdn: 2019-01-17T11:03:13Z DEBUG cn=ng 2019-01-17T11:03:13Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-search-filter: 2019-01-17T11:03:13Z DEBUG (objectclass=ipaNisNetgroup) 2019-01-17T11:03:13Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:03:13Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:03:13Z DEBUG cn=%{cn} 2019-01-17T11:03:13Z DEBUG schema-compat-search-base: 2019-01-17T11:03:13Z DEBUG cn=ng, cn=alt, dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-container-group: 2019-01-17T11:03:13Z DEBUG cn=compat, dc=local 2019-01-17T11:03:13Z DEBUG [(0, u'schema-compat-entry-attribute', [u'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","-",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","-"),%{nisDomainName:-})'])] 2019-01-17T11:03:13Z DEBUG Updated 1 2019-01-17T11:03:13Z DEBUG Done 2019-01-17T11:03:13Z DEBUG Updating existing entry: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:03:13Z DEBUG objectclass=sudoRole 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2019-01-17T11:03:13Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2019-01-17T11:03:13Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2019-01-17T11:03:13Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2019-01-17T11:03:13Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2019-01-17T11:03:13Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2019-01-17T11:03:13Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2019-01-17T11:03:13Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2019-01-17T11:03:13Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2019-01-17T11:03:13Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoOption=%{ipaSudoOpt} 2019-01-17T11:03:13Z DEBUG sudoOrder=%{sudoOrder} 2019-01-17T11:03:13Z DEBUG sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn") 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG sudoers 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:03:13Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2019-01-17T11:03:13Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:03:13Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-search-filter: 2019-01-17T11:03:13Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2019-01-17T11:03:13Z DEBUG schema-compat-search-base: 2019-01-17T11:03:13Z DEBUG cn=sudorules, cn=sudo, dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-container-group: 2019-01-17T11:03:13Z DEBUG ou=SUDOers, dc=local 2019-01-17T11:03:13Z DEBUG add: 'top' to objectClass, current value [u'top', u'extensibleObject'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'extensibleObject', u'top'] 2019-01-17T11:03:13Z DEBUG add: 'extensibleObject' to objectClass, current value [u'extensibleObject', u'top'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'top', u'extensibleObject'] 2019-01-17T11:03:13Z DEBUG add: 'sudoers' to cn, current value [u'sudoers'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'sudoers'] 2019-01-17T11:03:13Z DEBUG add: 'ou=SUDOers, dc=local' to schema-compat-container-group, current value [u'ou=SUDOers, dc=local'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'ou=SUDOers, dc=local'] 2019-01-17T11:03:13Z DEBUG add: 'cn=sudorules, cn=sudo, dc=local' to schema-compat-search-base, current value [u'cn=sudorules, cn=sudo, dc=local'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'cn=sudorules, cn=sudo, dc=local'] 2019-01-17T11:03:13Z DEBUG add: '(&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE)))' to schema-compat-search-filter, current value [u'(&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE)))'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'(&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE)))'] 2019-01-17T11:03:13Z DEBUG add: '%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")' to schema-compat-entry-rdn, current value [u'%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")'] 2019-01-17T11:03:13Z DEBUG add: 'objectclass=sudoRole' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole'] 2019-01-17T11:03:13Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")' to schema-compat-entry-attribute, current value [u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")'] 2019-01-17T11:03:13Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")")' to schema-compat-entry-attribute, current value [u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2019-01-17T11:03:13Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")")' to schema-compat-entry-attribute, current value [u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")'] 2019-01-17T11:03:13Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")")' to schema-compat-entry-attribute, current value [u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2019-01-17T11:03:13Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")")' to schema-compat-entry-attribute, current value [u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")'] 2019-01-17T11:03:13Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")' to schema-compat-entry-attribute, current value [u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")'] 2019-01-17T11:03:13Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")")' to schema-compat-entry-attribute, current value [u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")'] 2019-01-17T11:03:13Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")")' to schema-compat-entry-attribute, current value [u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")'] 2019-01-17T11:03:13Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")")' to schema-compat-entry-attribute, current value [u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")'] 2019-01-17T11:03:13Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")")' to schema-compat-entry-attribute, current value [u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")'] 2019-01-17T11:03:13Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")' to schema-compat-entry-attribute, current value [u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2019-01-17T11:03:13Z DEBUG add: 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")")' to schema-compat-entry-attribute, current value [u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")'] 2019-01-17T11:03:13Z DEBUG add: 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")")' to schema-compat-entry-attribute, current value [u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")'] 2019-01-17T11:03:13Z DEBUG add: 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")' to schema-compat-entry-attribute, current value [u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")'] 2019-01-17T11:03:13Z DEBUG add: 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")' to schema-compat-entry-attribute, current value [u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")'] 2019-01-17T11:03:13Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")' to schema-compat-entry-attribute, current value [u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")'] 2019-01-17T11:03:13Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")' to schema-compat-entry-attribute, current value [u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")'] 2019-01-17T11:03:13Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")")' to schema-compat-entry-attribute, current value [u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2019-01-17T11:03:13Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")")' to schema-compat-entry-attribute, current value [u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2019-01-17T11:03:13Z DEBUG add: 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")' to schema-compat-entry-attribute, current value [u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")'] 2019-01-17T11:03:13Z DEBUG add: 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")")' to schema-compat-entry-attribute, current value [u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2019-01-17T11:03:13Z DEBUG add: 'sudoOption=%{ipaSudoOpt}' to schema-compat-entry-attribute, current value [u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}'] 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:03:13Z DEBUG sudoOrder=%{sudoOrder} 2019-01-17T11:03:13Z DEBUG sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn") 2019-01-17T11:03:13Z DEBUG objectclass=sudoRole 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2019-01-17T11:03:13Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2019-01-17T11:03:13Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2019-01-17T11:03:13Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2019-01-17T11:03:13Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2019-01-17T11:03:13Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2019-01-17T11:03:13Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2019-01-17T11:03:13Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2019-01-17T11:03:13Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2019-01-17T11:03:13Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoOption=%{ipaSudoOpt} 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG sudoers 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:03:13Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2019-01-17T11:03:13Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:03:13Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-search-filter: 2019-01-17T11:03:13Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2019-01-17T11:03:13Z DEBUG schema-compat-search-base: 2019-01-17T11:03:13Z DEBUG cn=sudorules, cn=sudo, dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-container-group: 2019-01-17T11:03:13Z DEBUG ou=SUDOers, dc=local 2019-01-17T11:03:13Z DEBUG [] 2019-01-17T11:03:13Z DEBUG Updated 0 2019-01-17T11:03:13Z DEBUG Done 2019-01-17T11:03:13Z DEBUG Updating existing entry: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:03:13Z DEBUG objectclass=device 2019-01-17T11:03:13Z DEBUG objectclass=ieee802Device 2019-01-17T11:03:13Z DEBUG cn=%{fqdn} 2019-01-17T11:03:13Z DEBUG macAddress=%{macAddress} 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG computers 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG schema-compat-container-rdn: 2019-01-17T11:03:13Z DEBUG cn=computers 2019-01-17T11:03:13Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:03:13Z DEBUG cn=%first("%{fqdn}") 2019-01-17T11:03:13Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:03:13Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-search-filter: 2019-01-17T11:03:13Z DEBUG (&(macAddress=*)(fqdn=*)(objectClass=ipaHost)) 2019-01-17T11:03:13Z DEBUG schema-compat-search-base: 2019-01-17T11:03:13Z DEBUG cn=computers, cn=accounts, dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-container-group: 2019-01-17T11:03:13Z DEBUG cn=compat, dc=local 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:03:13Z DEBUG objectclass=device 2019-01-17T11:03:13Z DEBUG objectclass=ieee802Device 2019-01-17T11:03:13Z DEBUG cn=%{fqdn} 2019-01-17T11:03:13Z DEBUG macAddress=%{macAddress} 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG computers 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG schema-compat-container-rdn: 2019-01-17T11:03:13Z DEBUG cn=computers 2019-01-17T11:03:13Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:03:13Z DEBUG cn=%first("%{fqdn}") 2019-01-17T11:03:13Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:03:13Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-search-filter: 2019-01-17T11:03:13Z DEBUG (&(macAddress=*)(fqdn=*)(objectClass=ipaHost)) 2019-01-17T11:03:13Z DEBUG schema-compat-search-base: 2019-01-17T11:03:13Z DEBUG cn=computers, cn=accounts, dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-container-group: 2019-01-17T11:03:13Z DEBUG cn=compat, dc=local 2019-01-17T11:03:13Z DEBUG [] 2019-01-17T11:03:13Z DEBUG Updated 0 2019-01-17T11:03:13Z DEBUG Done 2019-01-17T11:03:13Z DEBUG Updating existing entry: oid=2.16.840.1.113730.3.4.9,cn=features,cn=config 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: oid=2.16.840.1.113730.3.4.9,cn=features,cn=config 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG directoryServerFeature 2019-01-17T11:03:13Z DEBUG aci: 2019-01-17T11:03:13Z DEBUG (targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; ) 2019-01-17T11:03:13Z DEBUG oid: 2019-01-17T11:03:13Z DEBUG 2.16.840.1.113730.3.4.9 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG VLV Request Control 2019-01-17T11:03:13Z DEBUG only: set aci to '(targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; )', current value [u'(targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; )'] 2019-01-17T11:03:13Z DEBUG only: updated value [u'(targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; )'] 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: oid=2.16.840.1.113730.3.4.9,cn=features,cn=config 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG directoryServerFeature 2019-01-17T11:03:13Z DEBUG aci: 2019-01-17T11:03:13Z DEBUG (targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; ) 2019-01-17T11:03:13Z DEBUG oid: 2019-01-17T11:03:13Z DEBUG 2.16.840.1.113730.3.4.9 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG VLV Request Control 2019-01-17T11:03:13Z DEBUG [] 2019-01-17T11:03:13Z DEBUG Updated 0 2019-01-17T11:03:13Z DEBUG Done 2019-01-17T11:03:13Z DEBUG Updating existing entry: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:03:13Z DEBUG objectclass=sudoRole 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2019-01-17T11:03:13Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2019-01-17T11:03:13Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2019-01-17T11:03:13Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2019-01-17T11:03:13Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2019-01-17T11:03:13Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2019-01-17T11:03:13Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2019-01-17T11:03:13Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2019-01-17T11:03:13Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2019-01-17T11:03:13Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoOption=%{ipaSudoOpt} 2019-01-17T11:03:13Z DEBUG sudoOrder=%{sudoOrder} 2019-01-17T11:03:13Z DEBUG sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn") 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG sudoers 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:03:13Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2019-01-17T11:03:13Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:03:13Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-search-filter: 2019-01-17T11:03:13Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2019-01-17T11:03:13Z DEBUG schema-compat-search-base: 2019-01-17T11:03:13Z DEBUG cn=sudorules, cn=sudo, dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-container-group: 2019-01-17T11:03:13Z DEBUG ou=SUDOers, dc=local 2019-01-17T11:03:13Z DEBUG only: set schema-compat-entry-rdn to '%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")', current value [u'%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")'] 2019-01-17T11:03:13Z DEBUG only: updated value [u'%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")'] 2019-01-17T11:03:13Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2019-01-17T11:03:13Z DEBUG add: 'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}'] 2019-01-17T11:03:13Z DEBUG remove: 'sudoRunAsGroup=%deref("ipaSudoRunAs","cn")' from schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}'] 2019-01-17T11:03:13Z DEBUG remove: 'sudoRunAsGroup=%deref("ipaSudoRunAs","cn")' not in schema-compat-entry-attribute 2019-01-17T11:03:13Z DEBUG remove: 'sudoRunAsUser=%{ipaSudoRunAsExtUser}' from schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}'] 2019-01-17T11:03:13Z DEBUG remove: 'sudoRunAsUser=%{ipaSudoRunAsExtUser}' not in schema-compat-entry-attribute 2019-01-17T11:03:13Z DEBUG remove: 'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}' from schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}'] 2019-01-17T11:03:13Z DEBUG remove: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2019-01-17T11:03:13Z DEBUG remove: 'sudoRunAsUser=%deref("ipaSudoRunAs","uid")' from schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2019-01-17T11:03:13Z DEBUG remove: 'sudoRunAsUser=%deref("ipaSudoRunAs","uid")' not in schema-compat-entry-attribute 2019-01-17T11:03:13Z DEBUG remove: 'sudoRunAsGroup=%{ipaSudoRunAsExtGroup}' from schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2019-01-17T11:03:13Z DEBUG remove: 'sudoRunAsGroup=%{ipaSudoRunAsExtGroup}' not in schema-compat-entry-attribute 2019-01-17T11:03:13Z DEBUG remove: 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")' from schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2019-01-17T11:03:13Z DEBUG remove: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:03:13Z DEBUG objectclass=sudoRole 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2019-01-17T11:03:13Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2019-01-17T11:03:13Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2019-01-17T11:03:13Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2019-01-17T11:03:13Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2019-01-17T11:03:13Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2019-01-17T11:03:13Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2019-01-17T11:03:13Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2019-01-17T11:03:13Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoOption=%{ipaSudoOpt} 2019-01-17T11:03:13Z DEBUG sudoOrder=%{sudoOrder} 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG sudoers 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:03:13Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2019-01-17T11:03:13Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:03:13Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-search-filter: 2019-01-17T11:03:13Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2019-01-17T11:03:13Z DEBUG schema-compat-search-base: 2019-01-17T11:03:13Z DEBUG cn=sudorules, cn=sudo, dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-container-group: 2019-01-17T11:03:13Z DEBUG ou=SUDOers, dc=local 2019-01-17T11:03:13Z DEBUG [(1, u'schema-compat-entry-attribute', [u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")'])] 2019-01-17T11:03:13Z DEBUG Updated 1 2019-01-17T11:03:13Z DEBUG Done 2019-01-17T11:03:13Z DEBUG Updating existing entry: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:03:13Z DEBUG objectclass=sudoRole 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2019-01-17T11:03:13Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2019-01-17T11:03:13Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2019-01-17T11:03:13Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2019-01-17T11:03:13Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2019-01-17T11:03:13Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2019-01-17T11:03:13Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2019-01-17T11:03:13Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2019-01-17T11:03:13Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2019-01-17T11:03:13Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoOption=%{ipaSudoOpt} 2019-01-17T11:03:13Z DEBUG sudoOrder=%{sudoOrder} 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG sudoers 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:03:13Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2019-01-17T11:03:13Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:03:13Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-search-filter: 2019-01-17T11:03:13Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2019-01-17T11:03:13Z DEBUG schema-compat-search-base: 2019-01-17T11:03:13Z DEBUG cn=sudorules, cn=sudo, dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-container-group: 2019-01-17T11:03:13Z DEBUG ou=SUDOers, dc=local 2019-01-17T11:03:13Z DEBUG add: 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")'] 2019-01-17T11:03:13Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")'] 2019-01-17T11:03:13Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")'] 2019-01-17T11:03:13Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2019-01-17T11:03:13Z DEBUG add: 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")'] 2019-01-17T11:03:13Z DEBUG add: 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")")' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2019-01-17T11:03:13Z DEBUG remove: 'cn=changelog' from schema-compat-ignore-subtree, current value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:03:13Z DEBUG remove: 'cn=changelog' not in schema-compat-ignore-subtree 2019-01-17T11:03:13Z DEBUG remove: 'o=ipaca' from schema-compat-ignore-subtree, current value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:03:13Z DEBUG remove: 'o=ipaca' not in schema-compat-ignore-subtree 2019-01-17T11:03:13Z DEBUG add: 'dc=local' to schema-compat-restrict-subtree, current value [u'dc=local', u'cn=Schema Compatibility,cn=plugins,cn=config'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'cn=Schema Compatibility,cn=plugins,cn=config', u'dc=local'] 2019-01-17T11:03:13Z DEBUG add: 'cn=Schema Compatibility,cn=plugins,cn=config' to schema-compat-restrict-subtree, current value [u'cn=Schema Compatibility,cn=plugins,cn=config', u'dc=local'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'dc=local', u'cn=Schema Compatibility,cn=plugins,cn=config'] 2019-01-17T11:03:13Z DEBUG add: 'cn=dna,cn=ipa,cn=etc,dc=local' to schema-compat-ignore-subtree, current value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'cn=topology,cn=ipa,cn=etc,dc=local', u'cn=dna,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:03:13Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=local' to schema-compat-ignore-subtree, current value [u'cn=topology,cn=ipa,cn=etc,dc=local', u'cn=dna,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:03:13Z DEBUG objectclass=sudoRole 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2019-01-17T11:03:13Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2019-01-17T11:03:13Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2019-01-17T11:03:13Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2019-01-17T11:03:13Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2019-01-17T11:03:13Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoOption=%{ipaSudoOpt} 2019-01-17T11:03:13Z DEBUG sudoOrder=%{sudoOrder} 2019-01-17T11:03:13Z DEBUG sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn") 2019-01-17T11:03:13Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2019-01-17T11:03:13Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2019-01-17T11:03:13Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2019-01-17T11:03:13Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2019-01-17T11:03:13Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG sudoers 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:03:13Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2019-01-17T11:03:13Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:03:13Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-search-filter: 2019-01-17T11:03:13Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2019-01-17T11:03:13Z DEBUG schema-compat-search-base: 2019-01-17T11:03:13Z DEBUG cn=sudorules, cn=sudo, dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-container-group: 2019-01-17T11:03:13Z DEBUG ou=SUDOers, dc=local 2019-01-17T11:03:13Z DEBUG [(0, u'schema-compat-entry-attribute', [u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")'])] 2019-01-17T11:03:13Z DEBUG Updated 1 2019-01-17T11:03:13Z DEBUG Done 2019-01-17T11:03:13Z DEBUG Updating existing entry: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:03:13Z DEBUG objectclass=nisNetgroup 2019-01-17T11:03:13Z DEBUG memberNisNetgroup=%deref_r("member","cn") 2019-01-17T11:03:13Z DEBUG nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","%ifeq(\"hostCategory\",\"all\",\"\",\"-\")",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","%ifeq(\"userCategory\",\"all\",\"\",\"-\")"),%{nisDomainName:-}) 2019-01-17T11:03:13Z DEBUG nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","-",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","-"),%{nisDomainName:-}) 2019-01-17T11:03:13Z DEBUG schema-compat-check-access: 2019-01-17T11:03:13Z DEBUG yes 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG ng 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG schema-compat-container-rdn: 2019-01-17T11:03:13Z DEBUG cn=ng 2019-01-17T11:03:13Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-search-filter: 2019-01-17T11:03:13Z DEBUG (objectclass=ipaNisNetgroup) 2019-01-17T11:03:13Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:03:13Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:03:13Z DEBUG cn=%{cn} 2019-01-17T11:03:13Z DEBUG schema-compat-search-base: 2019-01-17T11:03:13Z DEBUG cn=ng, cn=alt, dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-container-group: 2019-01-17T11:03:13Z DEBUG cn=compat, dc=local 2019-01-17T11:03:13Z DEBUG replace: updated value [u'objectclass=nisNetgroup', u'memberNisNetgroup=%deref_r("member","cn")', u'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"-\\")",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"-\\")"),%{nisDomainName:-})', u'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"-\\")",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"-\\")"),%{nisDomainName:-})'] 2019-01-17T11:03:13Z DEBUG remove: 'cn=changelog' from schema-compat-ignore-subtree, current value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:03:13Z DEBUG remove: 'cn=changelog' not in schema-compat-ignore-subtree 2019-01-17T11:03:13Z DEBUG remove: 'o=ipaca' from schema-compat-ignore-subtree, current value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:03:13Z DEBUG remove: 'o=ipaca' not in schema-compat-ignore-subtree 2019-01-17T11:03:13Z DEBUG add: 'dc=local' to schema-compat-restrict-subtree, current value [u'dc=local', u'cn=Schema Compatibility,cn=plugins,cn=config'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'cn=Schema Compatibility,cn=plugins,cn=config', u'dc=local'] 2019-01-17T11:03:13Z DEBUG add: 'cn=Schema Compatibility,cn=plugins,cn=config' to schema-compat-restrict-subtree, current value [u'cn=Schema Compatibility,cn=plugins,cn=config', u'dc=local'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'dc=local', u'cn=Schema Compatibility,cn=plugins,cn=config'] 2019-01-17T11:03:13Z DEBUG add: 'cn=dna,cn=ipa,cn=etc,dc=local' to schema-compat-ignore-subtree, current value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'cn=topology,cn=ipa,cn=etc,dc=local', u'cn=dna,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:03:13Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=local' to schema-compat-ignore-subtree, current value [u'cn=topology,cn=ipa,cn=etc,dc=local', u'cn=dna,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:03:13Z DEBUG objectclass=nisNetgroup 2019-01-17T11:03:13Z DEBUG memberNisNetgroup=%deref_r("member","cn") 2019-01-17T11:03:13Z DEBUG nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","%ifeq(\"hostCategory\",\"all\",\"\",\"-\")",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","%ifeq(\"userCategory\",\"all\",\"\",\"-\")"),%{nisDomainName:-}) 2019-01-17T11:03:13Z DEBUG nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","%ifeq(\"hostCategory\",\"all\",\"\",\"-\")",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","%ifeq(\"userCategory\",\"all\",\"\",\"-\")"),%{nisDomainName:-}) 2019-01-17T11:03:13Z DEBUG schema-compat-check-access: 2019-01-17T11:03:13Z DEBUG yes 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG ng 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG schema-compat-container-rdn: 2019-01-17T11:03:13Z DEBUG cn=ng 2019-01-17T11:03:13Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-search-filter: 2019-01-17T11:03:13Z DEBUG (objectclass=ipaNisNetgroup) 2019-01-17T11:03:13Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:03:13Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:03:13Z DEBUG cn=%{cn} 2019-01-17T11:03:13Z DEBUG schema-compat-search-base: 2019-01-17T11:03:13Z DEBUG cn=ng, cn=alt, dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-container-group: 2019-01-17T11:03:13Z DEBUG cn=compat, dc=local 2019-01-17T11:03:13Z DEBUG [(1, u'schema-compat-entry-attribute', [u'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","-",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","-"),%{nisDomainName:-})'])] 2019-01-17T11:03:13Z DEBUG Updated 1 2019-01-17T11:03:13Z DEBUG Done 2019-01-17T11:03:13Z DEBUG Updating existing entry: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:03:13Z DEBUG objectclass=device 2019-01-17T11:03:13Z DEBUG objectclass=ieee802Device 2019-01-17T11:03:13Z DEBUG cn=%{fqdn} 2019-01-17T11:03:13Z DEBUG macAddress=%{macAddress} 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG computers 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG schema-compat-container-rdn: 2019-01-17T11:03:13Z DEBUG cn=computers 2019-01-17T11:03:13Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:03:13Z DEBUG cn=%first("%{fqdn}") 2019-01-17T11:03:13Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:03:13Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-search-filter: 2019-01-17T11:03:13Z DEBUG (&(macAddress=*)(fqdn=*)(objectClass=ipaHost)) 2019-01-17T11:03:13Z DEBUG schema-compat-search-base: 2019-01-17T11:03:13Z DEBUG cn=computers, cn=accounts, dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-container-group: 2019-01-17T11:03:13Z DEBUG cn=compat, dc=local 2019-01-17T11:03:13Z DEBUG remove: 'cn=changelog' from schema-compat-ignore-subtree, current value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:03:13Z DEBUG remove: 'cn=changelog' not in schema-compat-ignore-subtree 2019-01-17T11:03:13Z DEBUG remove: 'o=ipaca' from schema-compat-ignore-subtree, current value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:03:13Z DEBUG remove: 'o=ipaca' not in schema-compat-ignore-subtree 2019-01-17T11:03:13Z DEBUG add: 'dc=local' to schema-compat-restrict-subtree, current value [u'dc=local', u'cn=Schema Compatibility,cn=plugins,cn=config'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'cn=Schema Compatibility,cn=plugins,cn=config', u'dc=local'] 2019-01-17T11:03:13Z DEBUG add: 'cn=Schema Compatibility,cn=plugins,cn=config' to schema-compat-restrict-subtree, current value [u'cn=Schema Compatibility,cn=plugins,cn=config', u'dc=local'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'dc=local', u'cn=Schema Compatibility,cn=plugins,cn=config'] 2019-01-17T11:03:13Z DEBUG add: 'cn=dna,cn=ipa,cn=etc,dc=local' to schema-compat-ignore-subtree, current value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'cn=topology,cn=ipa,cn=etc,dc=local', u'cn=dna,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:03:13Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=local' to schema-compat-ignore-subtree, current value [u'cn=topology,cn=ipa,cn=etc,dc=local', u'cn=dna,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:03:13Z DEBUG objectclass=device 2019-01-17T11:03:13Z DEBUG objectclass=ieee802Device 2019-01-17T11:03:13Z DEBUG cn=%{fqdn} 2019-01-17T11:03:13Z DEBUG macAddress=%{macAddress} 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG computers 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG schema-compat-container-rdn: 2019-01-17T11:03:13Z DEBUG cn=computers 2019-01-17T11:03:13Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:03:13Z DEBUG cn=%first("%{fqdn}") 2019-01-17T11:03:13Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:03:13Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-search-filter: 2019-01-17T11:03:13Z DEBUG (&(macAddress=*)(fqdn=*)(objectClass=ipaHost)) 2019-01-17T11:03:13Z DEBUG schema-compat-search-base: 2019-01-17T11:03:13Z DEBUG cn=computers, cn=accounts, dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-container-group: 2019-01-17T11:03:13Z DEBUG cn=compat, dc=local 2019-01-17T11:03:13Z DEBUG [] 2019-01-17T11:03:13Z DEBUG Updated 0 2019-01-17T11:03:13Z DEBUG Done 2019-01-17T11:03:13Z DEBUG Updating existing entry: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:03:13Z DEBUG objectclass=sudoRole 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2019-01-17T11:03:13Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2019-01-17T11:03:13Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2019-01-17T11:03:13Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2019-01-17T11:03:13Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2019-01-17T11:03:13Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2019-01-17T11:03:13Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2019-01-17T11:03:13Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2019-01-17T11:03:13Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2019-01-17T11:03:13Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoOption=%{ipaSudoOpt} 2019-01-17T11:03:13Z DEBUG sudoOrder=%{sudoOrder} 2019-01-17T11:03:13Z DEBUG sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn") 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG sudoers 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:03:13Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2019-01-17T11:03:13Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:03:13Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-search-filter: 2019-01-17T11:03:13Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2019-01-17T11:03:13Z DEBUG schema-compat-search-base: 2019-01-17T11:03:13Z DEBUG cn=sudorules, cn=sudo, dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-container-group: 2019-01-17T11:03:13Z DEBUG ou=SUDOers, dc=local 2019-01-17T11:03:13Z DEBUG add: 'sudoOrder=%{sudoOrder}' to schema-compat-entry-attribute, current value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoOrder=%{sudoOrder}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'objectclass=sudoRole', u'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', u'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', u'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', u'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', u'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', u'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', u'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', u'sudoOption=%{ipaSudoOpt}', u'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', u'sudoOrder=%{sudoOrder}'] 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:03:13Z DEBUG objectclass=sudoRole 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2019-01-17T11:03:13Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2019-01-17T11:03:13Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2019-01-17T11:03:13Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2019-01-17T11:03:13Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2019-01-17T11:03:13Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2019-01-17T11:03:13Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2019-01-17T11:03:13Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2019-01-17T11:03:13Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2019-01-17T11:03:13Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2019-01-17T11:03:13Z DEBUG sudoOption=%{ipaSudoOpt} 2019-01-17T11:03:13Z DEBUG sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn") 2019-01-17T11:03:13Z DEBUG sudoOrder=%{sudoOrder} 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG sudoers 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:03:13Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2019-01-17T11:03:13Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:03:13Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-search-filter: 2019-01-17T11:03:13Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2019-01-17T11:03:13Z DEBUG schema-compat-search-base: 2019-01-17T11:03:13Z DEBUG cn=sudorules, cn=sudo, dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-container-group: 2019-01-17T11:03:13Z DEBUG ou=SUDOers, dc=local 2019-01-17T11:03:13Z DEBUG [] 2019-01-17T11:03:13Z DEBUG Updated 0 2019-01-17T11:03:13Z DEBUG Done 2019-01-17T11:03:13Z DEBUG Updating existing entry: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:03:13Z DEBUG objectclass=posixAccount 2019-01-17T11:03:13Z DEBUG gecos=%{cn} 2019-01-17T11:03:13Z DEBUG cn=%{cn} 2019-01-17T11:03:13Z DEBUG uidNumber=%{uidNumber} 2019-01-17T11:03:13Z DEBUG gidNumber=%{gidNumber} 2019-01-17T11:03:13Z DEBUG loginShell=%{loginShell} 2019-01-17T11:03:13Z DEBUG homeDirectory=%{homeDirectory} 2019-01-17T11:03:13Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:03:13Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","") 2019-01-17T11:03:13Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2019-01-17T11:03:13Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:03:13Z DEBUG uid=%{uid} 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG users 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG schema-compat-container-rdn: 2019-01-17T11:03:13Z DEBUG cn=users 2019-01-17T11:03:13Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:03:13Z DEBUG uid=%first("%{uid}") 2019-01-17T11:03:13Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:03:13Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-search-filter: 2019-01-17T11:03:13Z DEBUG objectclass=posixAccount 2019-01-17T11:03:13Z DEBUG schema-compat-search-base: 2019-01-17T11:03:13Z DEBUG cn=users, cn=accounts, dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-container-group: 2019-01-17T11:03:13Z DEBUG cn=compat, dc=local 2019-01-17T11:03:13Z DEBUG remove: 'cn=changelog' from schema-compat-ignore-subtree, current value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:03:13Z DEBUG remove: 'cn=changelog' not in schema-compat-ignore-subtree 2019-01-17T11:03:13Z DEBUG remove: 'o=ipaca' from schema-compat-ignore-subtree, current value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:03:13Z DEBUG remove: 'o=ipaca' not in schema-compat-ignore-subtree 2019-01-17T11:03:13Z DEBUG add: 'dc=local' to schema-compat-restrict-subtree, current value [u'dc=local', u'cn=Schema Compatibility,cn=plugins,cn=config'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'cn=Schema Compatibility,cn=plugins,cn=config', u'dc=local'] 2019-01-17T11:03:13Z DEBUG add: 'cn=Schema Compatibility,cn=plugins,cn=config' to schema-compat-restrict-subtree, current value [u'cn=Schema Compatibility,cn=plugins,cn=config', u'dc=local'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'dc=local', u'cn=Schema Compatibility,cn=plugins,cn=config'] 2019-01-17T11:03:13Z DEBUG add: 'cn=dna,cn=ipa,cn=etc,dc=local' to schema-compat-ignore-subtree, current value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'cn=topology,cn=ipa,cn=etc,dc=local', u'cn=dna,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:03:13Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=local' to schema-compat-ignore-subtree, current value [u'cn=topology,cn=ipa,cn=etc,dc=local', u'cn=dna,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:03:13Z DEBUG objectclass=posixAccount 2019-01-17T11:03:13Z DEBUG gecos=%{cn} 2019-01-17T11:03:13Z DEBUG cn=%{cn} 2019-01-17T11:03:13Z DEBUG uidNumber=%{uidNumber} 2019-01-17T11:03:13Z DEBUG gidNumber=%{gidNumber} 2019-01-17T11:03:13Z DEBUG loginShell=%{loginShell} 2019-01-17T11:03:13Z DEBUG homeDirectory=%{homeDirectory} 2019-01-17T11:03:13Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:03:13Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","") 2019-01-17T11:03:13Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2019-01-17T11:03:13Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:03:13Z DEBUG uid=%{uid} 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG users 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG schema-compat-container-rdn: 2019-01-17T11:03:13Z DEBUG cn=users 2019-01-17T11:03:13Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:03:13Z DEBUG uid=%first("%{uid}") 2019-01-17T11:03:13Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:03:13Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-search-filter: 2019-01-17T11:03:13Z DEBUG objectclass=posixAccount 2019-01-17T11:03:13Z DEBUG schema-compat-search-base: 2019-01-17T11:03:13Z DEBUG cn=users, cn=accounts, dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-container-group: 2019-01-17T11:03:13Z DEBUG cn=compat, dc=local 2019-01-17T11:03:13Z DEBUG [] 2019-01-17T11:03:13Z DEBUG Updated 0 2019-01-17T11:03:13Z DEBUG Done 2019-01-17T11:03:13Z DEBUG Updating existing entry: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:03:13Z DEBUG objectclass=posixGroup 2019-01-17T11:03:13Z DEBUG gidNumber=%{gidNumber} 2019-01-17T11:03:13Z DEBUG memberUid=%{memberUid} 2019-01-17T11:03:13Z DEBUG memberUid=%deref_r("member","uid") 2019-01-17T11:03:13Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:03:13Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","") 2019-01-17T11:03:13Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2019-01-17T11:03:13Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:03:13Z DEBUG ipaexternalmember=%deref_r("member","ipaexternalmember") 2019-01-17T11:03:13Z DEBUG objectclass=ipaexternalgroup 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG groups 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG schema-compat-container-rdn: 2019-01-17T11:03:13Z DEBUG cn=groups 2019-01-17T11:03:13Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:03:13Z DEBUG cn=%{cn} 2019-01-17T11:03:13Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:03:13Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-search-filter: 2019-01-17T11:03:13Z DEBUG objectclass=posixGroup 2019-01-17T11:03:13Z DEBUG schema-compat-search-base: 2019-01-17T11:03:13Z DEBUG cn=groups, cn=accounts, dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-container-group: 2019-01-17T11:03:13Z DEBUG cn=compat, dc=local 2019-01-17T11:03:13Z DEBUG remove: 'cn=changelog' from schema-compat-ignore-subtree, current value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:03:13Z DEBUG remove: 'cn=changelog' not in schema-compat-ignore-subtree 2019-01-17T11:03:13Z DEBUG remove: 'o=ipaca' from schema-compat-ignore-subtree, current value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:03:13Z DEBUG remove: 'o=ipaca' not in schema-compat-ignore-subtree 2019-01-17T11:03:13Z DEBUG add: 'dc=local' to schema-compat-restrict-subtree, current value [u'dc=local', u'cn=Schema Compatibility,cn=plugins,cn=config'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'cn=Schema Compatibility,cn=plugins,cn=config', u'dc=local'] 2019-01-17T11:03:13Z DEBUG add: 'cn=Schema Compatibility,cn=plugins,cn=config' to schema-compat-restrict-subtree, current value [u'cn=Schema Compatibility,cn=plugins,cn=config', u'dc=local'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'dc=local', u'cn=Schema Compatibility,cn=plugins,cn=config'] 2019-01-17T11:03:13Z DEBUG add: 'cn=dna,cn=ipa,cn=etc,dc=local' to schema-compat-ignore-subtree, current value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'cn=topology,cn=ipa,cn=etc,dc=local', u'cn=dna,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:03:13Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=local' to schema-compat-ignore-subtree, current value [u'cn=topology,cn=ipa,cn=etc,dc=local', u'cn=dna,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'cn=dna,cn=ipa,cn=etc,dc=local', u'cn=topology,cn=ipa,cn=etc,dc=local'] 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:03:13Z DEBUG objectclass=posixGroup 2019-01-17T11:03:13Z DEBUG gidNumber=%{gidNumber} 2019-01-17T11:03:13Z DEBUG memberUid=%{memberUid} 2019-01-17T11:03:13Z DEBUG memberUid=%deref_r("member","uid") 2019-01-17T11:03:13Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:03:13Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","") 2019-01-17T11:03:13Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2019-01-17T11:03:13Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:03:13Z DEBUG ipaexternalmember=%deref_r("member","ipaexternalmember") 2019-01-17T11:03:13Z DEBUG objectclass=ipaexternalgroup 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG groups 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG schema-compat-container-rdn: 2019-01-17T11:03:13Z DEBUG cn=groups 2019-01-17T11:03:13Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:03:13Z DEBUG cn=%{cn} 2019-01-17T11:03:13Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:03:13Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-search-filter: 2019-01-17T11:03:13Z DEBUG objectclass=posixGroup 2019-01-17T11:03:13Z DEBUG schema-compat-search-base: 2019-01-17T11:03:13Z DEBUG cn=groups, cn=accounts, dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-container-group: 2019-01-17T11:03:13Z DEBUG cn=compat, dc=local 2019-01-17T11:03:13Z DEBUG [] 2019-01-17T11:03:13Z DEBUG Updated 0 2019-01-17T11:03:13Z DEBUG Done 2019-01-17T11:03:13Z DEBUG Updating existing entry: cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:03:13Z DEBUG on 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG Schema Compatibility 2019-01-17T11:03:13Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:13Z DEBUG none 2019-01-17T11:03:13Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:13Z DEBUG none 2019-01-17T11:03:13Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:13Z DEBUG off 2019-01-17T11:03:13Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:13Z DEBUG /usr/lib64/dirsrv/plugins/schemacompat-plugin.so 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG nsSlapdPlugin 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:13Z DEBUG none 2019-01-17T11:03:13Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:13Z DEBUG schema_compat_plugin_init 2019-01-17T11:03:13Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:03:13Z DEBUG 40 2019-01-17T11:03:13Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:13Z DEBUG object 2019-01-17T11:03:13Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:13Z DEBUG none 2019-01-17T11:03:13Z DEBUG add: '40' to nsslapd-pluginprecedence, current value [u'40'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'40'] 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG nsslapd-pluginbetxn: 2019-01-17T11:03:13Z DEBUG on 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG Schema Compatibility 2019-01-17T11:03:13Z DEBUG nsslapd-pluginVersion: 2019-01-17T11:03:13Z DEBUG none 2019-01-17T11:03:13Z DEBUG nsslapd-pluginDescription: 2019-01-17T11:03:13Z DEBUG none 2019-01-17T11:03:13Z DEBUG nsslapd-pluginEnabled: 2019-01-17T11:03:13Z DEBUG off 2019-01-17T11:03:13Z DEBUG nsslapd-pluginPath: 2019-01-17T11:03:13Z DEBUG /usr/lib64/dirsrv/plugins/schemacompat-plugin.so 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG nsSlapdPlugin 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG nsslapd-pluginId: 2019-01-17T11:03:13Z DEBUG none 2019-01-17T11:03:13Z DEBUG nsslapd-pluginInitfunc: 2019-01-17T11:03:13Z DEBUG schema_compat_plugin_init 2019-01-17T11:03:13Z DEBUG nsslapd-pluginprecedence: 2019-01-17T11:03:13Z DEBUG 40 2019-01-17T11:03:13Z DEBUG nsslapd-pluginType: 2019-01-17T11:03:13Z DEBUG object 2019-01-17T11:03:13Z DEBUG nsslapd-pluginVendor: 2019-01-17T11:03:13Z DEBUG none 2019-01-17T11:03:13Z DEBUG [] 2019-01-17T11:03:13Z DEBUG Updated 0 2019-01-17T11:03:13Z DEBUG Done 2019-01-17T11:03:13Z DEBUG Updating existing entry: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:03:13Z DEBUG objectclass=posixAccount 2019-01-17T11:03:13Z DEBUG gecos=%{cn} 2019-01-17T11:03:13Z DEBUG cn=%{cn} 2019-01-17T11:03:13Z DEBUG uidNumber=%{uidNumber} 2019-01-17T11:03:13Z DEBUG gidNumber=%{gidNumber} 2019-01-17T11:03:13Z DEBUG loginShell=%{loginShell} 2019-01-17T11:03:13Z DEBUG homeDirectory=%{homeDirectory} 2019-01-17T11:03:13Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:03:13Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","") 2019-01-17T11:03:13Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2019-01-17T11:03:13Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:03:13Z DEBUG uid=%{uid} 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG users 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG schema-compat-container-rdn: 2019-01-17T11:03:13Z DEBUG cn=users 2019-01-17T11:03:13Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:03:13Z DEBUG uid=%first("%{uid}") 2019-01-17T11:03:13Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:03:13Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-search-filter: 2019-01-17T11:03:13Z DEBUG objectclass=posixAccount 2019-01-17T11:03:13Z DEBUG schema-compat-search-base: 2019-01-17T11:03:13Z DEBUG cn=users, cn=accounts, dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-container-group: 2019-01-17T11:03:13Z DEBUG cn=compat, dc=local 2019-01-17T11:03:13Z DEBUG add: '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")' to schema-compat-entry-attribute, current value [u'objectclass=posixAccount', u'gecos=%{cn}', u'cn=%{cn}', u'uidNumber=%{uidNumber}', u'gidNumber=%{gidNumber}', u'loginShell=%{loginShell}', u'homeDirectory=%{homeDirectory}', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'uid=%{uid}'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'objectclass=posixAccount', u'gecos=%{cn}', u'cn=%{cn}', u'uidNumber=%{uidNumber}', u'gidNumber=%{gidNumber}', u'loginShell=%{loginShell}', u'homeDirectory=%{homeDirectory}', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'uid=%{uid}', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")'] 2019-01-17T11:03:13Z DEBUG add: '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")' to schema-compat-entry-attribute, current value [u'objectclass=posixAccount', u'gecos=%{cn}', u'cn=%{cn}', u'uidNumber=%{uidNumber}', u'gidNumber=%{gidNumber}', u'loginShell=%{loginShell}', u'homeDirectory=%{homeDirectory}', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'uid=%{uid}', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'objectclass=posixAccount', u'gecos=%{cn}', u'cn=%{cn}', u'uidNumber=%{uidNumber}', u'gidNumber=%{gidNumber}', u'loginShell=%{loginShell}', u'homeDirectory=%{homeDirectory}', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'uid=%{uid}', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")'] 2019-01-17T11:03:13Z DEBUG add: 'ipaanchoruuid=%{ipaanchoruuid}' to schema-compat-entry-attribute, current value [u'objectclass=posixAccount', u'gecos=%{cn}', u'cn=%{cn}', u'uidNumber=%{uidNumber}', u'gidNumber=%{gidNumber}', u'loginShell=%{loginShell}', u'homeDirectory=%{homeDirectory}', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'uid=%{uid}', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'objectclass=posixAccount', u'gecos=%{cn}', u'cn=%{cn}', u'uidNumber=%{uidNumber}', u'gidNumber=%{gidNumber}', u'loginShell=%{loginShell}', u'homeDirectory=%{homeDirectory}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'uid=%{uid}', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}'] 2019-01-17T11:03:13Z DEBUG add: '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")' to schema-compat-entry-attribute, current value [u'objectclass=posixAccount', u'gecos=%{cn}', u'cn=%{cn}', u'uidNumber=%{uidNumber}', u'gidNumber=%{gidNumber}', u'loginShell=%{loginShell}', u'homeDirectory=%{homeDirectory}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'uid=%{uid}', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'objectclass=posixAccount', u'gecos=%{cn}', u'cn=%{cn}', u'uidNumber=%{uidNumber}', u'gidNumber=%{gidNumber}', u'loginShell=%{loginShell}', u'homeDirectory=%{homeDirectory}', u'uid=%{uid}', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")'] 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:03:13Z DEBUG objectclass=posixAccount 2019-01-17T11:03:13Z DEBUG gecos=%{cn} 2019-01-17T11:03:13Z DEBUG cn=%{cn} 2019-01-17T11:03:13Z DEBUG uidNumber=%{uidNumber} 2019-01-17T11:03:13Z DEBUG gidNumber=%{gidNumber} 2019-01-17T11:03:13Z DEBUG loginShell=%{loginShell} 2019-01-17T11:03:13Z DEBUG homeDirectory=%{homeDirectory} 2019-01-17T11:03:13Z DEBUG uid=%{uid} 2019-01-17T11:03:13Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:03:13Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","") 2019-01-17T11:03:13Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2019-01-17T11:03:13Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG users 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG schema-compat-container-rdn: 2019-01-17T11:03:13Z DEBUG cn=users 2019-01-17T11:03:13Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:03:13Z DEBUG uid=%first("%{uid}") 2019-01-17T11:03:13Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:03:13Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-search-filter: 2019-01-17T11:03:13Z DEBUG objectclass=posixAccount 2019-01-17T11:03:13Z DEBUG schema-compat-search-base: 2019-01-17T11:03:13Z DEBUG cn=users, cn=accounts, dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-container-group: 2019-01-17T11:03:13Z DEBUG cn=compat, dc=local 2019-01-17T11:03:13Z DEBUG [] 2019-01-17T11:03:13Z DEBUG Updated 0 2019-01-17T11:03:13Z DEBUG Done 2019-01-17T11:03:13Z DEBUG Updating existing entry: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:03:13Z DEBUG objectclass=posixGroup 2019-01-17T11:03:13Z DEBUG gidNumber=%{gidNumber} 2019-01-17T11:03:13Z DEBUG memberUid=%{memberUid} 2019-01-17T11:03:13Z DEBUG memberUid=%deref_r("member","uid") 2019-01-17T11:03:13Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:03:13Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","") 2019-01-17T11:03:13Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2019-01-17T11:03:13Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:03:13Z DEBUG ipaexternalmember=%deref_r("member","ipaexternalmember") 2019-01-17T11:03:13Z DEBUG objectclass=ipaexternalgroup 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG groups 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG schema-compat-container-rdn: 2019-01-17T11:03:13Z DEBUG cn=groups 2019-01-17T11:03:13Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:03:13Z DEBUG cn=%{cn} 2019-01-17T11:03:13Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:03:13Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-search-filter: 2019-01-17T11:03:13Z DEBUG objectclass=posixGroup 2019-01-17T11:03:13Z DEBUG schema-compat-search-base: 2019-01-17T11:03:13Z DEBUG cn=groups, cn=accounts, dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-container-group: 2019-01-17T11:03:13Z DEBUG cn=compat, dc=local 2019-01-17T11:03:13Z DEBUG add: '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")' to schema-compat-entry-attribute, current value [u'objectclass=posixGroup', u'gidNumber=%{gidNumber}', u'memberUid=%{memberUid}', u'memberUid=%deref_r("member","uid")', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'ipaexternalmember=%deref_r("member","ipaexternalmember")', u'objectclass=ipaexternalgroup'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'objectclass=posixGroup', u'gidNumber=%{gidNumber}', u'memberUid=%{memberUid}', u'memberUid=%deref_r("member","uid")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'ipaexternalmember=%deref_r("member","ipaexternalmember")', u'objectclass=ipaexternalgroup', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")'] 2019-01-17T11:03:13Z DEBUG add: '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")' to schema-compat-entry-attribute, current value [u'objectclass=posixGroup', u'gidNumber=%{gidNumber}', u'memberUid=%{memberUid}', u'memberUid=%deref_r("member","uid")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'ipaexternalmember=%deref_r("member","ipaexternalmember")', u'objectclass=ipaexternalgroup', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'objectclass=posixGroup', u'gidNumber=%{gidNumber}', u'memberUid=%{memberUid}', u'memberUid=%deref_r("member","uid")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'ipaexternalmember=%deref_r("member","ipaexternalmember")', u'objectclass=ipaexternalgroup', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")'] 2019-01-17T11:03:13Z DEBUG add: 'ipaanchoruuid=%{ipaanchoruuid}' to schema-compat-entry-attribute, current value [u'objectclass=posixGroup', u'gidNumber=%{gidNumber}', u'memberUid=%{memberUid}', u'memberUid=%deref_r("member","uid")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'ipaexternalmember=%deref_r("member","ipaexternalmember")', u'objectclass=ipaexternalgroup', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'objectclass=posixGroup', u'gidNumber=%{gidNumber}', u'memberUid=%{memberUid}', u'memberUid=%deref_r("member","uid")', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'ipaexternalmember=%deref_r("member","ipaexternalmember")', u'objectclass=ipaexternalgroup', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}'] 2019-01-17T11:03:13Z DEBUG add: '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")' to schema-compat-entry-attribute, current value [u'objectclass=posixGroup', u'gidNumber=%{gidNumber}', u'memberUid=%{memberUid}', u'memberUid=%deref_r("member","uid")', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'ipaexternalmember=%deref_r("member","ipaexternalmember")', u'objectclass=ipaexternalgroup', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'objectclass=posixGroup', u'gidNumber=%{gidNumber}', u'memberUid=%{memberUid}', u'memberUid=%deref_r("member","uid")', u'ipaexternalmember=%deref_r("member","ipaexternalmember")', u'objectclass=ipaexternalgroup', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")'] 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:03:13Z DEBUG objectclass=posixGroup 2019-01-17T11:03:13Z DEBUG gidNumber=%{gidNumber} 2019-01-17T11:03:13Z DEBUG memberUid=%{memberUid} 2019-01-17T11:03:13Z DEBUG memberUid=%deref_r("member","uid") 2019-01-17T11:03:13Z DEBUG ipaexternalmember=%deref_r("member","ipaexternalmember") 2019-01-17T11:03:13Z DEBUG objectclass=ipaexternalgroup 2019-01-17T11:03:13Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:03:13Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","") 2019-01-17T11:03:13Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2019-01-17T11:03:13Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG groups 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG schema-compat-container-rdn: 2019-01-17T11:03:13Z DEBUG cn=groups 2019-01-17T11:03:13Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:03:13Z DEBUG cn=%{cn} 2019-01-17T11:03:13Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:03:13Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-search-filter: 2019-01-17T11:03:13Z DEBUG objectclass=posixGroup 2019-01-17T11:03:13Z DEBUG schema-compat-search-base: 2019-01-17T11:03:13Z DEBUG cn=groups, cn=accounts, dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-container-group: 2019-01-17T11:03:13Z DEBUG cn=compat, dc=local 2019-01-17T11:03:13Z DEBUG [] 2019-01-17T11:03:13Z DEBUG Updated 0 2019-01-17T11:03:13Z DEBUG Done 2019-01-17T11:03:13Z DEBUG Updating existing entry: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Initial value 2019-01-17T11:03:13Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:03:13Z DEBUG objectclass=posixAccount 2019-01-17T11:03:13Z DEBUG gecos=%{cn} 2019-01-17T11:03:13Z DEBUG cn=%{cn} 2019-01-17T11:03:13Z DEBUG uidNumber=%{uidNumber} 2019-01-17T11:03:13Z DEBUG gidNumber=%{gidNumber} 2019-01-17T11:03:13Z DEBUG loginShell=%{loginShell} 2019-01-17T11:03:13Z DEBUG homeDirectory=%{homeDirectory} 2019-01-17T11:03:13Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:03:13Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","") 2019-01-17T11:03:13Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2019-01-17T11:03:13Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:03:13Z DEBUG uid=%{uid} 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG users 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG schema-compat-container-rdn: 2019-01-17T11:03:13Z DEBUG cn=users 2019-01-17T11:03:13Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:03:13Z DEBUG uid=%first("%{uid}") 2019-01-17T11:03:13Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:03:13Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-search-filter: 2019-01-17T11:03:13Z DEBUG objectclass=posixAccount 2019-01-17T11:03:13Z DEBUG schema-compat-search-base: 2019-01-17T11:03:13Z DEBUG cn=users, cn=accounts, dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-container-group: 2019-01-17T11:03:13Z DEBUG cn=compat, dc=local 2019-01-17T11:03:13Z DEBUG add: 'uid=%{uid}' to schema-compat-entry-attribute, current value [u'objectclass=posixAccount', u'gecos=%{cn}', u'cn=%{cn}', u'uidNumber=%{uidNumber}', u'gidNumber=%{gidNumber}', u'loginShell=%{loginShell}', u'homeDirectory=%{homeDirectory}', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'uid=%{uid}'] 2019-01-17T11:03:13Z DEBUG add: updated value [u'objectclass=posixAccount', u'gecos=%{cn}', u'cn=%{cn}', u'uidNumber=%{uidNumber}', u'gidNumber=%{gidNumber}', u'loginShell=%{loginShell}', u'homeDirectory=%{homeDirectory}', u'%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', u'%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","")', u'ipaanchoruuid=%{ipaanchoruuid}', u'%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', u'uid=%{uid}'] 2019-01-17T11:03:13Z DEBUG replace: uid=%{uid} not found, skipping 2019-01-17T11:03:13Z DEBUG --------------------------------------------- 2019-01-17T11:03:13Z DEBUG Final value after applying updates 2019-01-17T11:03:13Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-attribute: 2019-01-17T11:03:13Z DEBUG objectclass=posixAccount 2019-01-17T11:03:13Z DEBUG gecos=%{cn} 2019-01-17T11:03:13Z DEBUG cn=%{cn} 2019-01-17T11:03:13Z DEBUG uidNumber=%{uidNumber} 2019-01-17T11:03:13Z DEBUG gidNumber=%{gidNumber} 2019-01-17T11:03:13Z DEBUG loginShell=%{loginShell} 2019-01-17T11:03:13Z DEBUG homeDirectory=%{homeDirectory} 2019-01-17T11:03:13Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:03:13Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:local:%{ipauniqueid}","") 2019-01-17T11:03:13Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2019-01-17T11:03:13Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2019-01-17T11:03:13Z DEBUG uid=%{uid} 2019-01-17T11:03:13Z DEBUG cn: 2019-01-17T11:03:13Z DEBUG users 2019-01-17T11:03:13Z DEBUG objectClass: 2019-01-17T11:03:13Z DEBUG top 2019-01-17T11:03:13Z DEBUG extensibleObject 2019-01-17T11:03:13Z DEBUG schema-compat-container-rdn: 2019-01-17T11:03:13Z DEBUG cn=users 2019-01-17T11:03:13Z DEBUG schema-compat-restrict-subtree: 2019-01-17T11:03:13Z DEBUG dc=local 2019-01-17T11:03:13Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2019-01-17T11:03:13Z DEBUG schema-compat-entry-rdn: 2019-01-17T11:03:13Z DEBUG uid=%first("%{uid}") 2019-01-17T11:03:13Z DEBUG schema-compat-ignore-subtree: 2019-01-17T11:03:13Z DEBUG cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-search-filter: 2019-01-17T11:03:13Z DEBUG objectclass=posixAccount 2019-01-17T11:03:13Z DEBUG schema-compat-search-base: 2019-01-17T11:03:13Z DEBUG cn=users, cn=accounts, dc=local 2019-01-17T11:03:13Z DEBUG schema-compat-container-group: 2019-01-17T11:03:13Z DEBUG cn=compat, dc=local 2019-01-17T11:03:13Z DEBUG [] 2019-01-17T11:03:13Z DEBUG Updated 0 2019-01-17T11:03:13Z DEBUG Done 2019-01-17T11:03:13Z DEBUG Parsing update file '/usr/share/ipa/updates/90-post_upgrade_plugins.update' 2019-01-17T11:03:13Z DEBUG Executing upgrade plugin: update_ca_topology 2019-01-17T11:03:13Z DEBUG raw: update_ca_topology 2019-01-17T11:03:13Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:13Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2019-01-17T11:03:13Z DEBUG importing all plugin modules in ipaserver.plugins... 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.aci 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.automember 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.automount 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.baseldap 2019-01-17T11:03:13Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.baseuser 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.batch 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.ca 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.caacl 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.cert 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.certmap 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.certprofile 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.config 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.delegation 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.dns 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.dogtag 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.group 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.hbac 2019-01-17T11:03:13Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.hbactest 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.host 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.idrange 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.idviews 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.internal 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.join 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.ldap2 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.location 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.migration 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.misc 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.netgroup 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.otp 2019-01-17T11:03:13Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.otptoken 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.passwd 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.permission 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.ping 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.pkinit 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.privilege 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.rabase 2019-01-17T11:03:13Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.role 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.schema 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.selfservice 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.server 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.serverrole 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.serverroles 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.service 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.session 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.stageuser 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.sudo 2019-01-17T11:03:13Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.sudorule 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.topology 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.trust 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.user 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.vault 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.virtual 2019-01-17T11:03:13Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.whoami 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2019-01-17T11:03:13Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.install.plugins.dns 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2019-01-17T11:03:13Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2019-01-17T11:03:14Z DEBUG Created connection context.ldap2_139822027035216 2019-01-17T11:03:14Z DEBUG Destroyed connection context.ldap2_139822027035216 2019-01-17T11:03:14Z DEBUG Created connection context.ldap2_139822027035216 2019-01-17T11:03:14Z DEBUG Parsing update file '/usr/share/ipa/ca-topology.uldif' 2019-01-17T11:03:14Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-LOCAL.socket from SchemaCache 2019-01-17T11:03:14Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LOCAL.socket conn= 2019-01-17T11:03:15Z DEBUG Updating existing entry: cn=centos75.local,cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:15Z DEBUG --------------------------------------------- 2019-01-17T11:03:15Z DEBUG Initial value 2019-01-17T11:03:15Z DEBUG dn: cn=centos75.local,cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:15Z DEBUG objectClass: 2019-01-17T11:03:15Z DEBUG top 2019-01-17T11:03:15Z DEBUG nsContainer 2019-01-17T11:03:15Z DEBUG ipaReplTopoManagedServer 2019-01-17T11:03:15Z DEBUG ipaConfigObject 2019-01-17T11:03:15Z DEBUG ipaSupportedDomainLevelConfig 2019-01-17T11:03:15Z DEBUG ipaMaxDomainLevel: 2019-01-17T11:03:15Z DEBUG 1 2019-01-17T11:03:15Z DEBUG ipaMinDomainLevel: 2019-01-17T11:03:15Z DEBUG 0 2019-01-17T11:03:15Z DEBUG cn: 2019-01-17T11:03:15Z DEBUG centos75.local 2019-01-17T11:03:15Z DEBUG ipaReplTopoManagedSuffix: 2019-01-17T11:03:15Z DEBUG dc=local 2019-01-17T11:03:15Z DEBUG add: 'ipaReplTopoManagedServer' to objectclass, current value [u'top', u'nsContainer', u'ipaReplTopoManagedServer', u'ipaConfigObject', u'ipaSupportedDomainLevelConfig'] 2019-01-17T11:03:15Z DEBUG add: updated value [u'top', u'nsContainer', u'ipaConfigObject', u'ipaSupportedDomainLevelConfig', u'ipaReplTopoManagedServer'] 2019-01-17T11:03:15Z DEBUG add: 'o=ipaca' to ipaReplTopoManagedSuffix, current value [u'dc=local'] 2019-01-17T11:03:15Z DEBUG add: updated value [u'dc=local', u'o=ipaca'] 2019-01-17T11:03:15Z DEBUG --------------------------------------------- 2019-01-17T11:03:15Z DEBUG Final value after applying updates 2019-01-17T11:03:15Z DEBUG dn: cn=centos75.local,cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:15Z DEBUG objectClass: 2019-01-17T11:03:15Z DEBUG top 2019-01-17T11:03:15Z DEBUG nsContainer 2019-01-17T11:03:15Z DEBUG ipaConfigObject 2019-01-17T11:03:15Z DEBUG ipaSupportedDomainLevelConfig 2019-01-17T11:03:15Z DEBUG ipaReplTopoManagedServer 2019-01-17T11:03:15Z DEBUG ipaMaxDomainLevel: 2019-01-17T11:03:15Z DEBUG 1 2019-01-17T11:03:15Z DEBUG ipaMinDomainLevel: 2019-01-17T11:03:15Z DEBUG 0 2019-01-17T11:03:15Z DEBUG cn: 2019-01-17T11:03:15Z DEBUG centos75.local 2019-01-17T11:03:15Z DEBUG ipaReplTopoManagedSuffix: 2019-01-17T11:03:15Z DEBUG dc=local 2019-01-17T11:03:15Z DEBUG o=ipaca 2019-01-17T11:03:15Z DEBUG [(0, u'ipaReplTopoManagedSuffix', [u'o=ipaca'])] 2019-01-17T11:03:15Z DEBUG Updated 1 2019-01-17T11:03:15Z DEBUG Done 2019-01-17T11:03:15Z DEBUG New entry: cn=ca,cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:15Z DEBUG --------------------------------------------- 2019-01-17T11:03:15Z DEBUG Initial value 2019-01-17T11:03:15Z DEBUG dn: cn=ca,cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:15Z DEBUG objectclass: 2019-01-17T11:03:15Z DEBUG top 2019-01-17T11:03:15Z DEBUG iparepltopoconf 2019-01-17T11:03:15Z DEBUG cn: 2019-01-17T11:03:15Z DEBUG ca 2019-01-17T11:03:15Z DEBUG ipaReplTopoConfRoot: 2019-01-17T11:03:15Z DEBUG o=ipaca 2019-01-17T11:03:15Z DEBUG --------------------------------------------- 2019-01-17T11:03:15Z DEBUG Final value after applying updates 2019-01-17T11:03:15Z DEBUG dn: cn=ca,cn=topology,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:15Z DEBUG objectclass: 2019-01-17T11:03:15Z DEBUG top 2019-01-17T11:03:15Z DEBUG iparepltopoconf 2019-01-17T11:03:15Z DEBUG cn: 2019-01-17T11:03:15Z DEBUG ca 2019-01-17T11:03:15Z DEBUG ipaReplTopoConfRoot: 2019-01-17T11:03:15Z DEBUG o=ipaca 2019-01-17T11:03:15Z DEBUG New entry: cn=replica,cn=o\=ipaca,cn=mapping tree,cn=config 2019-01-17T11:03:15Z DEBUG --------------------------------------------- 2019-01-17T11:03:15Z DEBUG Initial value 2019-01-17T11:03:15Z DEBUG dn: cn=replica,cn=o\=ipaca,cn=mapping tree,cn=config 2019-01-17T11:03:15Z DEBUG onlyifexist: 'cn=replication managers,cn=sysaccounts,cn=etc,dc=local' to nsds5replicabinddngroup, current value [] 2019-01-17T11:03:15Z DEBUG --------------------------------------------- 2019-01-17T11:03:15Z DEBUG Final value after applying updates 2019-01-17T11:03:15Z DEBUG dn: cn=replica,cn=o\=ipaca,cn=mapping tree,cn=config 2019-01-17T11:03:15Z DEBUG Destroyed connection context.ldap2_139822027035216 2019-01-17T11:03:15Z DEBUG Executing upgrade plugin: update_ipaconfigstring_dnsversion_to_ipadnsversion 2019-01-17T11:03:15Z DEBUG raw: update_ipaconfigstring_dnsversion_to_ipadnsversion 2019-01-17T11:03:15Z DEBUG Executing upgrade plugin: update_dnszones 2019-01-17T11:03:15Z DEBUG raw: update_dnszones 2019-01-17T11:03:15Z DEBUG Executing upgrade plugin: update_dns_limits 2019-01-17T11:03:15Z DEBUG raw: update_dns_limits 2019-01-17T11:03:15Z DEBUG Executing upgrade plugin: update_sigden_extdom_broken_config 2019-01-17T11:03:15Z DEBUG raw: update_sigden_extdom_broken_config 2019-01-17T11:03:15Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:15Z DEBUG Already done, skipping 2019-01-17T11:03:15Z DEBUG Executing upgrade plugin: update_sids 2019-01-17T11:03:15Z DEBUG raw: update_sids 2019-01-17T11:03:15Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:15Z DEBUG SIDs do not need to be generated 2019-01-17T11:03:15Z DEBUG Executing upgrade plugin: update_default_range 2019-01-17T11:03:15Z DEBUG raw: update_default_range 2019-01-17T11:03:15Z DEBUG default_range: ipaDomainIDRange entry found, skip plugin 2019-01-17T11:03:15Z DEBUG Executing upgrade plugin: update_default_trust_view 2019-01-17T11:03:15Z DEBUG raw: update_default_trust_view 2019-01-17T11:03:15Z DEBUG raw: adtrust_is_enabled(version=u'2.229') 2019-01-17T11:03:15Z DEBUG adtrust_is_enabled(version=u'2.229') 2019-01-17T11:03:15Z DEBUG AD Trusts are not enabled on this server 2019-01-17T11:03:15Z DEBUG Executing upgrade plugin: update_tdo_gidnumber 2019-01-17T11:03:15Z DEBUG raw: update_tdo_gidnumber 2019-01-17T11:03:15Z DEBUG raw: adtrust_is_enabled(version=u'2.229') 2019-01-17T11:03:15Z DEBUG adtrust_is_enabled(version=u'2.229') 2019-01-17T11:03:15Z DEBUG AD Trusts are not enabled on this server 2019-01-17T11:03:15Z DEBUG Executing upgrade plugin: update_ca_renewal_master 2019-01-17T11:03:15Z DEBUG raw: update_ca_renewal_master 2019-01-17T11:03:15Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:15Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2019-01-17T11:03:15Z DEBUG found CA renewal master centos75.local 2019-01-17T11:03:15Z DEBUG Executing upgrade plugin: update_idrange_type 2019-01-17T11:03:15Z DEBUG raw: update_idrange_type 2019-01-17T11:03:15Z DEBUG update_idrange_type: search for ID ranges with no type set 2019-01-17T11:03:15Z DEBUG update_idrange_type: no ID range without type set found 2019-01-17T11:03:15Z DEBUG Executing upgrade plugin: update_pacs 2019-01-17T11:03:15Z DEBUG raw: update_pacs 2019-01-17T11:03:15Z DEBUG Adding nfs:NONE to default PAC types 2019-01-17T11:03:15Z DEBUG Executing upgrade plugin: update_service_principalalias 2019-01-17T11:03:15Z DEBUG raw: update_service_principalalias 2019-01-17T11:03:15Z DEBUG update_service_principalalias: search for affected services 2019-01-17T11:03:15Z DEBUG update_service_principalalias: found 2 services to update, truncated: False 2019-01-17T11:03:15Z DEBUG update_service_principalalias: all affected services updated 2019-01-17T11:03:15Z DEBUG Executing upgrade plugin: update_fix_duplicate_cacrt_in_ldap 2019-01-17T11:03:15Z DEBUG raw: update_fix_duplicate_cacrt_in_ldap 2019-01-17T11:03:15Z DEBUG raw: ca_is_enabled(version=u'2.229') 2019-01-17T11:03:15Z DEBUG ca_is_enabled(version=u'2.229') 2019-01-17T11:03:15Z DEBUG Found 1 entrie(s) for IPA CA in LDAP 2019-01-17T11:03:15Z DEBUG Destroyed connection context.ldap2_139822039370512 2019-01-17T11:03:15Z DEBUG Restarting directory server to apply updates 2019-01-17T11:03:15Z DEBUG Destroyed connection context.ldap2_139822069897104 2019-01-17T11:03:15Z DEBUG Starting external process 2019-01-17T11:03:15Z DEBUG args=/bin/systemctl restart dirsrv@LOCAL.service 2019-01-17T11:03:21Z DEBUG Process finished, return code=0 2019-01-17T11:03:21Z DEBUG stdout= 2019-01-17T11:03:21Z DEBUG stderr= 2019-01-17T11:03:21Z DEBUG Restart of dirsrv@LOCAL.service complete 2019-01-17T11:03:21Z DEBUG Created connection context.ldap2_139822069897104 2019-01-17T11:03:21Z DEBUG Created connection context.ldap2_139822039370512 2019-01-17T11:03:21Z DEBUG Executing upgrade plugin: update_upload_cacrt 2019-01-17T11:03:21Z DEBUG raw: update_upload_cacrt 2019-01-17T11:03:21Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2019-01-17T11:03:21Z DEBUG raw: ca_is_enabled(version=u'2.229') 2019-01-17T11:03:21Z DEBUG ca_is_enabled(version=u'2.229') 2019-01-17T11:03:21Z DEBUG flushing ldapi://%2Fvar%2Frun%2Fslapd-LOCAL.socket from SchemaCache 2019-01-17T11:03:21Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Fvar%2Frun%2Fslapd-LOCAL.socket conn= 2019-01-17T11:03:21Z DEBUG Starting external process 2019-01-17T11:03:21Z DEBUG args=/usr/bin/certutil -d dbm:/etc/httpd/alias -L -f /etc/httpd/alias/pwdfile.txt 2019-01-17T11:03:21Z DEBUG Process finished, return code=0 2019-01-17T11:03:21Z DEBUG stdout= Certificate Nickname Trust Attributes SSL,S/MIME,JAR/XPI Server-Cert u,u,u LOCAL IPA CA CT,C,C 2019-01-17T11:03:21Z DEBUG stderr= 2019-01-17T11:03:21Z DEBUG Starting external process 2019-01-17T11:03:21Z DEBUG args=/usr/bin/certutil -d dbm:/etc/httpd/alias -L -n LOCAL IPA CA -a -f /etc/httpd/alias/pwdfile.txt 2019-01-17T11:03:21Z DEBUG Process finished, return code=0 2019-01-17T11:03:21Z DEBUG stdout=-----BEGIN CERTIFICATE----- MIIDeTCCAmGgAwIBAgIBATANBgkqhkiG9w0BAQsFADAwMQ4wDAYDVQQKDAVMT0NB TDEeMBwGA1UEAwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB4XDTE5MDExNzEwMzY0 MFoXDTM5MDExNzEwMzY0MFowMDEOMAwGA1UECgwFTE9DQUwxHjAcBgNVBAMMFUNl cnRpZmljYXRlIEF1dGhvcml0eTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoC ggEBAKZb97CB23Y/pVfUJDKG0Ul69AV+VipQ/VG6X4Xj16a07871RLLHMSx7p4dH kLmLe0R876dzQEE+z6fR0DXaCMISDlS9Bq9uVrAKKCYQRfT7O6TloVYbseh2os2h xdublLnJEZjwVDhyB6fhjfdx8GtPBETiLM37M7ZY9+6No+WkjSrPHlxPEzV/a8cB FN/iHQ1+5/Hbvc1NG5V67DJy+WLNRRYhMi9v7OSF8BbSl8ApHJMM0qYNLhvKuY5V N8nRDB0vwkea2cywI2wG9c2/vufzzh8F0MBMIpkL/LtanaBtZ0C6oSLsqGVBS+0q d8sQ5zZFAzdipndQd6xuzwmc6C0CAwEAAaOBnTCBmjAfBgNVHSMEGDAWgBRUEnLK tz1ZHkZQdIH6aDD/IGomxDAPBgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB/wQEAwIB xjAdBgNVHQ4EFgQUVBJyyrc9WR5GUHSB+mgw/yBqJsQwNwYIKwYBBQUHAQEEKzAp MCcGCCsGAQUFBzABhhtodHRwOi8vaXBhLWNhLmxvY2FsL2NhL29jc3AwDQYJKoZI hvcNAQELBQADggEBAI+bg4Nwz7fO3xdpD4X73ASnWPIWJoF3NX1qrn0vWjImbqyI gixTCWf2YXEGYYOU1czGj+M14HPVC8cKZBpobPY7ESZNDVrl07/iqkumdooibeqW KMo0UsOX9iNcnLtJdCXl7+yKlzUm16C8Ud+b0WuXmWwUg+DPf/xveYLw9058AoyA ODURXE1hx8J/tQKV03pmJ5CQfetVCxUyqUvHf50IV9+Td2fQAyIIt2rQExRn1R0a TmZPFeUVkbIDYITl79GQKHXSfJkCAFgzUR2EA0kmBZcCwzGM3Iqh1YUUQE9BPreb 3fWVexLT8Q7y4qP/qTxidd8SG0OGwFRkBH0fhFs= -----END CERTIFICATE----- 2019-01-17T11:03:21Z DEBUG stderr= 2019-01-17T11:03:21Z DEBUG Executing upgrade plugin: update_ra_cert_store 2019-01-17T11:03:21Z DEBUG raw: update_ra_cert_store 2019-01-17T11:03:21Z DEBUG raw: ca_is_enabled(version=u'2.229') 2019-01-17T11:03:21Z DEBUG ca_is_enabled(version=u'2.229') 2019-01-17T11:03:21Z DEBUG Starting external process 2019-01-17T11:03:21Z DEBUG args=/usr/bin/certutil -d dbm:/etc/httpd/alias -L -n ipaCert -a -f /etc/httpd/alias/pwdfile.txt 2019-01-17T11:03:22Z DEBUG Process finished, return code=255 2019-01-17T11:03:22Z DEBUG stdout= 2019-01-17T11:03:22Z DEBUG stderr=certutil: Could not find cert: ipaCert : PR_FILE_NOT_FOUND_ERROR: File not found 2019-01-17T11:03:22Z DEBUG Executing upgrade plugin: update_master_to_dnsforwardzones 2019-01-17T11:03:22Z DEBUG raw: update_master_to_dnsforwardzones 2019-01-17T11:03:22Z DEBUG raw: dnsconfig_show(all=True, version=u'2.229') 2019-01-17T11:03:22Z DEBUG dnsconfig_show(rights=False, all=True, raw=False, version=u'2.229') 2019-01-17T11:03:22Z DEBUG Executing upgrade plugin: update_dnsforward_emptyzones 2019-01-17T11:03:22Z DEBUG raw: update_dnsforward_emptyzones 2019-01-17T11:03:22Z DEBUG raw: dnsconfig_show(all=True, version=u'2.229') 2019-01-17T11:03:22Z DEBUG dnsconfig_show(rights=False, all=True, raw=False, version=u'2.229') 2019-01-17T11:03:22Z DEBUG Executing upgrade plugin: update_managed_post 2019-01-17T11:03:22Z DEBUG raw: update_managed_post 2019-01-17T11:03:22Z DEBUG Executing upgrade plugin: update_managed_permissions 2019-01-17T11:03:22Z DEBUG raw: update_managed_permissions 2019-01-17T11:03:22Z DEBUG Anonymous ACI not found 2019-01-17T11:03:22Z DEBUG Updating managed permissions for automember 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Read Automember Definitions 2019-01-17T11:03:22Z DEBUG No changes to permission: System: Read Automember Definitions 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Read Automember Rules 2019-01-17T11:03:22Z DEBUG No changes to permission: System: Read Automember Rules 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Read Automember Tasks 2019-01-17T11:03:22Z DEBUG No changes to permission: System: Read Automember Tasks 2019-01-17T11:03:22Z DEBUG Updating managed permissions for automountkey 2019-01-17T11:03:22Z DEBUG Legacy permission Add Automount keys not found 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Add Automount Keys 2019-01-17T11:03:22Z DEBUG No changes to permission: System: Add Automount Keys 2019-01-17T11:03:22Z DEBUG Legacy permission Modify Automount keys not found 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Modify Automount Keys 2019-01-17T11:03:22Z DEBUG No changes to permission: System: Modify Automount Keys 2019-01-17T11:03:22Z DEBUG Legacy permission Remove Automount keys not found 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Remove Automount Keys 2019-01-17T11:03:22Z DEBUG No changes to permission: System: Remove Automount Keys 2019-01-17T11:03:22Z DEBUG Updating managed permissions for automountlocation 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Add Automount Locations 2019-01-17T11:03:22Z DEBUG No changes to permission: System: Add Automount Locations 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Read Automount Configuration 2019-01-17T11:03:22Z DEBUG No changes to permission: System: Read Automount Configuration 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Remove Automount Locations 2019-01-17T11:03:22Z DEBUG No changes to permission: System: Remove Automount Locations 2019-01-17T11:03:22Z DEBUG Updating managed permissions for automountmap 2019-01-17T11:03:22Z DEBUG Legacy permission Add Automount maps not found 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Add Automount Maps 2019-01-17T11:03:22Z DEBUG No changes to permission: System: Add Automount Maps 2019-01-17T11:03:22Z DEBUG Legacy permission Modify Automount maps not found 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Modify Automount Maps 2019-01-17T11:03:22Z DEBUG No changes to permission: System: Modify Automount Maps 2019-01-17T11:03:22Z DEBUG Legacy permission Remove Automount maps not found 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Remove Automount Maps 2019-01-17T11:03:22Z DEBUG No changes to permission: System: Remove Automount Maps 2019-01-17T11:03:22Z DEBUG Updating managed permissions for ca 2019-01-17T11:03:22Z DEBUG Legacy permission Add CA not found 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Add CA 2019-01-17T11:03:22Z DEBUG No changes to permission: System: Add CA 2019-01-17T11:03:22Z DEBUG Legacy permission Delete CA not found 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Delete CA 2019-01-17T11:03:22Z DEBUG No changes to permission: System: Delete CA 2019-01-17T11:03:22Z DEBUG Legacy permission Modify CA not found 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Modify CA 2019-01-17T11:03:22Z DEBUG No changes to permission: System: Modify CA 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Read CAs 2019-01-17T11:03:22Z DEBUG No changes to permission: System: Read CAs 2019-01-17T11:03:22Z DEBUG Updating managed permissions for caacl 2019-01-17T11:03:22Z DEBUG Legacy permission Add CA ACL not found 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Add CA ACL 2019-01-17T11:03:22Z DEBUG No changes to permission: System: Add CA ACL 2019-01-17T11:03:22Z DEBUG Legacy permission Delete CA ACL not found 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Delete CA ACL 2019-01-17T11:03:22Z DEBUG No changes to permission: System: Delete CA ACL 2019-01-17T11:03:22Z DEBUG Legacy permission Manage CA ACL membership not found 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Manage CA ACL Membership 2019-01-17T11:03:22Z DEBUG No changes to permission: System: Manage CA ACL Membership 2019-01-17T11:03:22Z DEBUG Legacy permission Modify CA ACL not found 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Modify CA ACL 2019-01-17T11:03:22Z DEBUG No changes to permission: System: Modify CA ACL 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Read CA ACLs 2019-01-17T11:03:22Z DEBUG No changes to permission: System: Read CA ACLs 2019-01-17T11:03:22Z DEBUG Updating managed permissions for certmapconfig 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Modify Certmap Configuration 2019-01-17T11:03:22Z DEBUG No changes to permission: System: Modify Certmap Configuration 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Read Certmap Configuration 2019-01-17T11:03:22Z DEBUG Updating ACI for managed permission: System: Read Certmap Configuration 2019-01-17T11:03:22Z DEBUG Adding ACI u'(targetattr = "cn || ipacertmappromptusername")(targetfilter = "(objectclass=ipacertmapconfigobject)")(version 3.0;acl "permission:System: Read Certmap Configuration";allow (compare,read,search) userdn = "ldap:///all";)' to cn=certmap,dc=local 2019-01-17T11:03:22Z DEBUG Updating managed permissions for certmaprule 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Add Certmap Rules 2019-01-17T11:03:22Z DEBUG Updating ACI for managed permission: System: Add Certmap Rules 2019-01-17T11:03:22Z DEBUG Adding ACI u'(targetfilter = "(objectclass=ipacertmaprule)")(version 3.0;acl "permission:System: Add Certmap Rules";allow (add) groupdn = "ldap:///cn=System: Add Certmap Rules,cn=permissions,cn=pbac,dc=local";)' to cn=certmaprules,cn=certmap,dc=local 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Delete Certmap Rules 2019-01-17T11:03:22Z DEBUG Updating ACI for managed permission: System: Delete Certmap Rules 2019-01-17T11:03:22Z DEBUG Adding ACI u'(targetfilter = "(objectclass=ipacertmaprule)")(version 3.0;acl "permission:System: Delete Certmap Rules";allow (delete) groupdn = "ldap:///cn=System: Delete Certmap Rules,cn=permissions,cn=pbac,dc=local";)' to cn=certmaprules,cn=certmap,dc=local 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Modify Certmap Rules 2019-01-17T11:03:22Z DEBUG Updating ACI for managed permission: System: Modify Certmap Rules 2019-01-17T11:03:22Z DEBUG Adding ACI u'(targetattr = "associateddomain || cn || description || ipacertmapmaprule || ipacertmapmatchrule || ipacertmappriority || ipaenabledflag || objectclass")(targetfilter = "(objectclass=ipacertmaprule)")(version 3.0;acl "permission:System: Modify Certmap Rules";allow (write) groupdn = "ldap:///cn=System: Modify Certmap Rules,cn=permissions,cn=pbac,dc=local";)' to cn=certmaprules,cn=certmap,dc=local 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Read Certmap Rules 2019-01-17T11:03:22Z DEBUG Updating ACI for managed permission: System: Read Certmap Rules 2019-01-17T11:03:22Z DEBUG Adding ACI u'(targetattr = "associateddomain || cn || createtimestamp || description || entryusn || ipacertmapmaprule || ipacertmapmatchrule || ipacertmappriority || ipaenabledflag || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipacertmaprule)")(version 3.0;acl "permission:System: Read Certmap Rules";allow (compare,read,search) userdn = "ldap:///all";)' to cn=certmaprules,cn=certmap,dc=local 2019-01-17T11:03:22Z DEBUG Updating managed permissions for certprofile 2019-01-17T11:03:22Z DEBUG Legacy permission Delete Certificate Profile not found 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Delete Certificate Profile 2019-01-17T11:03:22Z DEBUG Updating ACI for managed permission: System: Delete Certificate Profile 2019-01-17T11:03:22Z DEBUG Adding ACI u'(targetfilter = "(objectclass=ipacertprofile)")(version 3.0;acl "permission:System: Delete Certificate Profile";allow (delete) groupdn = "ldap:///cn=System: Delete Certificate Profile,cn=permissions,cn=pbac,dc=local";)' to cn=certprofiles,cn=ca,dc=local 2019-01-17T11:03:22Z DEBUG Legacy permission Import Certificate Profile not found 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Import Certificate Profile 2019-01-17T11:03:22Z DEBUG Updating ACI for managed permission: System: Import Certificate Profile 2019-01-17T11:03:22Z DEBUG Adding ACI u'(targetfilter = "(objectclass=ipacertprofile)")(version 3.0;acl "permission:System: Import Certificate Profile";allow (add) groupdn = "ldap:///cn=System: Import Certificate Profile,cn=permissions,cn=pbac,dc=local";)' to cn=certprofiles,cn=ca,dc=local 2019-01-17T11:03:22Z DEBUG Legacy permission Modify Certificate Profile not found 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Modify Certificate Profile 2019-01-17T11:03:22Z DEBUG Updating ACI for managed permission: System: Modify Certificate Profile 2019-01-17T11:03:22Z DEBUG Adding ACI u'(targetattr = "cn || description || ipacertprofilestoreissued")(targetfilter = "(objectclass=ipacertprofile)")(version 3.0;acl "permission:System: Modify Certificate Profile";allow (write) groupdn = "ldap:///cn=System: Modify Certificate Profile,cn=permissions,cn=pbac,dc=local";)' to cn=certprofiles,cn=ca,dc=local 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Read Certificate Profiles 2019-01-17T11:03:22Z DEBUG Updating ACI for managed permission: System: Read Certificate Profiles 2019-01-17T11:03:22Z DEBUG Adding ACI u'(targetattr = "cn || createtimestamp || description || entryusn || ipacertprofilestoreissued || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipacertprofile)")(version 3.0;acl "permission:System: Read Certificate Profiles";allow (compare,read,search) userdn = "ldap:///all";)' to cn=certprofiles,cn=ca,dc=local 2019-01-17T11:03:22Z DEBUG Updating managed permissions for config 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Read Global Configuration 2019-01-17T11:03:22Z DEBUG Updating ACI for managed permission: System: Read Global Configuration 2019-01-17T11:03:22Z DEBUG Adding ACI u'(targetattr = "cn || createtimestamp || entryusn || ipacertificatesubjectbase || ipaconfigstring || ipacustomfields || ipadefaultemaildomain || ipadefaultloginshell || ipadefaultprimarygroup || ipadomainresolutionorder || ipagroupobjectclasses || ipagroupsearchfields || ipahomesrootdir || ipakrbauthzdata || ipamaxusernamelength || ipamigrationenabled || ipapwdexpadvnotify || ipasearchrecordslimit || ipasearchtimelimit || ipaselinuxusermapdefault || ipaselinuxusermaporder || ipauserauthtype || ipauserobjectclasses || ipausersearchfields || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaguiconfig)")(version 3.0;acl "permission:System: Read Global Configuration";allow (compare,read,search) userdn = "ldap:///all";)' to cn=ipaConfig,cn=etc,dc=local 2019-01-17T11:03:22Z DEBUG Updating managed permissions for cosentry 2019-01-17T11:03:22Z DEBUG Legacy permission Add Group Password Policy costemplate not found 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Add Group Password Policy costemplate 2019-01-17T11:03:22Z DEBUG Updating ACI for managed permission: System: Add Group Password Policy costemplate 2019-01-17T11:03:22Z DEBUG Adding ACI u'(targetfilter = "(objectclass=costemplate)")(version 3.0;acl "permission:System: Add Group Password Policy costemplate";allow (add) groupdn = "ldap:///cn=System: Add Group Password Policy costemplate,cn=permissions,cn=pbac,dc=local";)' to cn=cosTemplates,cn=accounts,dc=local 2019-01-17T11:03:22Z DEBUG Legacy permission Delete Group Password Policy costemplate not found 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Delete Group Password Policy costemplate 2019-01-17T11:03:22Z DEBUG Updating ACI for managed permission: System: Delete Group Password Policy costemplate 2019-01-17T11:03:22Z DEBUG Adding ACI u'(targetfilter = "(objectclass=costemplate)")(version 3.0;acl "permission:System: Delete Group Password Policy costemplate";allow (delete) groupdn = "ldap:///cn=System: Delete Group Password Policy costemplate,cn=permissions,cn=pbac,dc=local";)' to cn=cosTemplates,cn=accounts,dc=local 2019-01-17T11:03:22Z DEBUG Legacy permission Modify Group Password Policy costemplate not found 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Modify Group Password Policy costemplate 2019-01-17T11:03:22Z DEBUG Updating ACI for managed permission: System: Modify Group Password Policy costemplate 2019-01-17T11:03:22Z DEBUG Adding ACI u'(targetattr = "cospriority")(targetfilter = "(objectclass=costemplate)")(version 3.0;acl "permission:System: Modify Group Password Policy costemplate";allow (write) groupdn = "ldap:///cn=System: Modify Group Password Policy costemplate,cn=permissions,cn=pbac,dc=local";)' to cn=cosTemplates,cn=accounts,dc=local 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Read Group Password Policy costemplate 2019-01-17T11:03:22Z DEBUG Updating ACI for managed permission: System: Read Group Password Policy costemplate 2019-01-17T11:03:22Z DEBUG Adding ACI u'(targetattr = "cn || cospriority || createtimestamp || entryusn || krbpwdpolicyreference || modifytimestamp || objectclass")(targetfilter = "(objectclass=costemplate)")(version 3.0;acl "permission:System: Read Group Password Policy costemplate";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Group Password Policy costemplate,cn=permissions,cn=pbac,dc=local";)' to cn=cosTemplates,cn=accounts,dc=local 2019-01-17T11:03:22Z DEBUG Updating managed permissions for dnsconfig 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Read DNS Configuration 2019-01-17T11:03:22Z DEBUG Updating ACI for managed permission: System: Read DNS Configuration 2019-01-17T11:03:22Z DEBUG Adding ACI u'(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=local")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=local";)' to dc=local 2019-01-17T11:03:22Z DEBUG Legacy permission Write DNS Configuration not found 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Write DNS Configuration 2019-01-17T11:03:22Z DEBUG Updating ACI for managed permission: System: Write DNS Configuration 2019-01-17T11:03:22Z DEBUG Adding ACI u'(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=local")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=local";)' to dc=local 2019-01-17T11:03:22Z DEBUG Updating managed permissions for dnsserver 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Modify DNS Servers Configuration 2019-01-17T11:03:22Z DEBUG Updating ACI for managed permission: System: Modify DNS Servers Configuration 2019-01-17T11:03:22Z DEBUG Adding ACI u'(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=local";)' to dc=local 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Read DNS Servers Configuration 2019-01-17T11:03:22Z DEBUG Updating ACI for managed permission: System: Read DNS Servers Configuration 2019-01-17T11:03:22Z DEBUG Adding ACI u'(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=local";)' to dc=local 2019-01-17T11:03:22Z DEBUG Updating managed permissions for dnszone 2019-01-17T11:03:22Z DEBUG Legacy permission add dns entries not found 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Add DNS Entries 2019-01-17T11:03:22Z DEBUG Updating ACI for managed permission: System: Add DNS Entries 2019-01-17T11:03:22Z DEBUG Adding ACI u'(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=local";)' to dc=local 2019-01-17T11:03:22Z DEBUG Updating managed permission: System: Manage DNSSEC keys 2019-01-17T11:03:23Z DEBUG Updating ACI for managed permission: System: Manage DNSSEC keys 2019-01-17T11:03:23Z DEBUG Adding ACI u'(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=local")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=local";)' to dc=local 2019-01-17T11:03:23Z DEBUG Updating managed permission: System: Manage DNSSEC metadata 2019-01-17T11:03:23Z DEBUG Updating ACI for managed permission: System: Manage DNSSEC metadata 2019-01-17T11:03:23Z DEBUG Adding ACI u'(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=local")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=local";)' to dc=local 2019-01-17T11:03:23Z DEBUG Updating managed permission: System: Read DNS Entries 2019-01-17T11:03:23Z DEBUG Updating ACI for managed permission: System: Read DNS Entries 2019-01-17T11:03:23Z DEBUG Adding ACI u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=local";)' to dc=local 2019-01-17T11:03:23Z DEBUG Legacy permission 'Read DNS Entries' not found 2019-01-17T11:03:23Z DEBUG Updating managed permission: System: Read DNSSEC metadata 2019-01-17T11:03:23Z DEBUG Updating ACI for managed permission: System: Read DNSSEC metadata 2019-01-17T11:03:23Z DEBUG Adding ACI u'(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=local")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=local";)' to dc=local 2019-01-17T11:03:23Z DEBUG Legacy permission remove dns entries not found 2019-01-17T11:03:23Z DEBUG Updating managed permission: System: Remove DNS Entries 2019-01-17T11:03:23Z DEBUG Updating ACI for managed permission: System: Remove DNS Entries 2019-01-17T11:03:23Z DEBUG Adding ACI u'(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=local";)' to dc=local 2019-01-17T11:03:23Z DEBUG Legacy permission update dns entries not found 2019-01-17T11:03:23Z DEBUG Updating managed permission: System: Update DNS Entries 2019-01-17T11:03:23Z DEBUG Updating ACI for managed permission: System: Update DNS Entries 2019-01-17T11:03:23Z DEBUG Adding ACI u'(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=local")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=local";)' to dc=local 2019-01-17T11:03:23Z DEBUG Updating managed permissions for group 2019-01-17T11:03:23Z DEBUG Legacy permission Add Groups not found 2019-01-17T11:03:23Z DEBUG Updating managed permission: System: Add Groups 2019-01-17T11:03:23Z DEBUG Updating ACI for managed permission: System: Add Groups 2019-01-17T11:03:23Z DEBUG Adding ACI u'(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Add Groups";allow (add) groupdn = "ldap:///cn=System: Add Groups,cn=permissions,cn=pbac,dc=local";)' to cn=groups,cn=accounts,dc=local 2019-01-17T11:03:23Z DEBUG Updating managed permission: System: Modify External Group Membership 2019-01-17T11:03:23Z DEBUG Updating ACI for managed permission: System: Modify External Group Membership 2019-01-17T11:03:23Z DEBUG Adding ACI u'(targetattr = "ipaexternalmember")(targetfilter = "(objectclass=ipaexternalgroup)")(version 3.0;acl "permission:System: Modify External Group Membership";allow (write) groupdn = "ldap:///cn=System: Modify External Group Membership,cn=permissions,cn=pbac,dc=local";)' to cn=groups,cn=accounts,dc=local 2019-01-17T11:03:23Z DEBUG Legacy permission Modify Group membership not found 2019-01-17T11:03:23Z DEBUG Updating managed permission: System: Modify Group Membership 2019-01-17T11:03:23Z DEBUG Updating ACI for managed permission: System: Modify Group Membership 2019-01-17T11:03:23Z DEBUG Adding ACI u'(targetattr = "member")(targetfilter = "(&(!(cn=admins))(objectclass=ipausergroup))")(version 3.0;acl "permission:System: Modify Group Membership";allow (write) groupdn = "ldap:///cn=System: Modify Group Membership,cn=permissions,cn=pbac,dc=local";)' to cn=groups,cn=accounts,dc=local 2019-01-17T11:03:23Z DEBUG Legacy permission Modify Groups not found 2019-01-17T11:03:23Z DEBUG Updating managed permission: System: Modify Groups 2019-01-17T11:03:23Z DEBUG Updating ACI for managed permission: System: Modify Groups 2019-01-17T11:03:23Z DEBUG Adding ACI u'(targetattr = "cn || description || gidnumber || ipauniqueid || mepmanagedby || objectclass")(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Modify Groups";allow (write) groupdn = "ldap:///cn=System: Modify Groups,cn=permissions,cn=pbac,dc=local";)' to cn=groups,cn=accounts,dc=local 2019-01-17T11:03:23Z DEBUG Updating managed permission: System: Read External Group Membership 2019-01-17T11:03:23Z DEBUG Updating ACI for managed permission: System: Read External Group Membership 2019-01-17T11:03:23Z DEBUG Adding ACI u'(targetattr = "ipaexternalmember")(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Read External Group Membership";allow (compare,read,search) userdn = "ldap:///all";)' to cn=groups,cn=accounts,dc=local 2019-01-17T11:03:23Z DEBUG Updating managed permission: System: Read Group Compat Tree 2019-01-17T11:03:23Z DEBUG Updating ACI for managed permission: System: Read Group Compat Tree 2019-01-17T11:03:23Z DEBUG Adding ACI u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=local")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)' to dc=local 2019-01-17T11:03:23Z DEBUG Updating managed permission: System: Read Group Membership 2019-01-17T11:03:23Z DEBUG Updating ACI for managed permission: System: Read Group Membership 2019-01-17T11:03:23Z DEBUG Adding ACI u'(targetattr = "member || memberhost || memberof || memberuid || memberuser")(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Read Group Membership";allow (compare,read,search) userdn = "ldap:///all";)' to cn=groups,cn=accounts,dc=local 2019-01-17T11:03:23Z DEBUG Updating managed permission: System: Read Group Views Compat Tree 2019-01-17T11:03:23Z DEBUG Updating ACI for managed permission: System: Read Group Views Compat Tree 2019-01-17T11:03:23Z DEBUG Adding ACI u'(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=local")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)' to dc=local 2019-01-17T11:03:23Z DEBUG Updating managed permission: System: Read Groups 2019-01-17T11:03:23Z DEBUG Updating ACI for managed permission: System: Read Groups 2019-01-17T11:03:23Z DEBUG Adding ACI u'(targetattr = "businesscategory || cn || createtimestamp || description || entryusn || gidnumber || ipaexternalmember || ipantsecurityidentifier || ipauniqueid || mepmanagedby || modifytimestamp || o || objectclass || ou || owner || seealso")(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Read Groups";allow (compare,read,search) userdn = "ldap:///anyone";)' to cn=groups,cn=accounts,dc=local 2019-01-17T11:03:23Z DEBUG Legacy permission Remove Groups not found 2019-01-17T11:03:23Z DEBUG Updating managed permission: System: Remove Groups 2019-01-17T11:03:23Z DEBUG Updating ACI for managed permission: System: Remove Groups 2019-01-17T11:03:23Z DEBUG Adding ACI u'(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Remove Groups";allow (delete) groupdn = "ldap:///cn=System: Remove Groups,cn=permissions,cn=pbac,dc=local";)' to cn=groups,cn=accounts,dc=local 2019-01-17T11:03:23Z DEBUG Updating managed permissions for hbacrule 2019-01-17T11:03:23Z DEBUG Legacy permission Add HBAC rule not found 2019-01-17T11:03:23Z DEBUG Updating managed permission: System: Add HBAC Rule 2019-01-17T11:03:23Z DEBUG Updating ACI for managed permission: System: Add HBAC Rule 2019-01-17T11:03:23Z DEBUG Adding ACI u'(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Add HBAC Rule";allow (add) groupdn = "ldap:///cn=System: Add HBAC Rule,cn=permissions,cn=pbac,dc=local";)' to cn=hbac,dc=local 2019-01-17T11:03:23Z DEBUG Legacy permission Delete HBAC rule not found 2019-01-17T11:03:23Z DEBUG Updating managed permission: System: Delete HBAC Rule 2019-01-17T11:03:23Z DEBUG Updating ACI for managed permission: System: Delete HBAC Rule 2019-01-17T11:03:23Z DEBUG Adding ACI u'(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Delete HBAC Rule";allow (delete) groupdn = "ldap:///cn=System: Delete HBAC Rule,cn=permissions,cn=pbac,dc=local";)' to cn=hbac,dc=local 2019-01-17T11:03:23Z DEBUG Legacy permission Manage HBAC rule membership not found 2019-01-17T11:03:23Z DEBUG Updating managed permission: System: Manage HBAC Rule Membership 2019-01-17T11:03:23Z DEBUG Updating ACI for managed permission: System: Manage HBAC Rule Membership 2019-01-17T11:03:23Z DEBUG Adding ACI u'(targetattr = "externalhost || memberhost || memberservice || memberuser")(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Manage HBAC Rule Membership";allow (write) groupdn = "ldap:///cn=System: Manage HBAC Rule Membership,cn=permissions,cn=pbac,dc=local";)' to cn=hbac,dc=local 2019-01-17T11:03:23Z DEBUG Legacy permission Modify HBAC rule not found 2019-01-17T11:03:23Z DEBUG Updating managed permission: System: Modify HBAC Rule 2019-01-17T11:03:23Z DEBUG Updating ACI for managed permission: System: Modify HBAC Rule 2019-01-17T11:03:23Z DEBUG Adding ACI u'(targetattr = "accessruletype || accesstime || cn || description || hostcategory || ipaenabledflag || servicecategory || sourcehost || sourcehostcategory || usercategory")(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Modify HBAC Rule";allow (write) groupdn = "ldap:///cn=System: Modify HBAC Rule,cn=permissions,cn=pbac,dc=local";)' to cn=hbac,dc=local 2019-01-17T11:03:23Z DEBUG Updating managed permission: System: Read HBAC Rules 2019-01-17T11:03:23Z DEBUG Updating ACI for managed permission: System: Read HBAC Rules 2019-01-17T11:03:23Z DEBUG Adding ACI u'(targetattr = "accessruletype || accesstime || cn || createtimestamp || description || entryusn || externalhost || hostcategory || ipaenabledflag || ipauniqueid || member || memberhost || memberservice || memberuser || modifytimestamp || objectclass || servicecategory || sourcehost || sourcehostcategory || usercategory")(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Read HBAC Rules";allow (compare,read,search) userdn = "ldap:///all";)' to cn=hbac,dc=local 2019-01-17T11:03:23Z DEBUG Updating managed permissions for hbacsvc 2019-01-17T11:03:23Z DEBUG Legacy permission Add HBAC services not found 2019-01-17T11:03:23Z DEBUG Updating managed permission: System: Add HBAC Services 2019-01-17T11:03:23Z DEBUG Updating ACI for managed permission: System: Add HBAC Services 2019-01-17T11:03:23Z DEBUG Adding ACI u'(targetfilter = "(objectclass=ipahbacservice)")(version 3.0;acl "permission:System: Add HBAC Services";allow (add) groupdn = "ldap:///cn=System: Add HBAC Services,cn=permissions,cn=pbac,dc=local";)' to cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:03:23Z DEBUG Legacy permission Delete HBAC services not found 2019-01-17T11:03:23Z DEBUG Updating managed permission: System: Delete HBAC Services 2019-01-17T11:03:23Z DEBUG Updating ACI for managed permission: System: Delete HBAC Services 2019-01-17T11:03:23Z DEBUG Adding ACI u'(targetfilter = "(objectclass=ipahbacservice)")(version 3.0;acl "permission:System: Delete HBAC Services";allow (delete) groupdn = "ldap:///cn=System: Delete HBAC Services,cn=permissions,cn=pbac,dc=local";)' to cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:03:23Z DEBUG Updating managed permission: System: Read HBAC Services 2019-01-17T11:03:23Z DEBUG Updating ACI for managed permission: System: Read HBAC Services 2019-01-17T11:03:23Z DEBUG Adding ACI u'(targetattr = "cn || createtimestamp || description || entryusn || ipauniqueid || memberof || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipahbacservice)")(version 3.0;acl "permission:System: Read HBAC Services";allow (compare,read,search) userdn = "ldap:///all";)' to cn=hbacservices,cn=hbac,dc=local 2019-01-17T11:03:23Z DEBUG Updating managed permissions for hbacsvcgroup 2019-01-17T11:03:23Z DEBUG Legacy permission Add HBAC service groups not found 2019-01-17T11:03:23Z DEBUG Updating managed permission: System: Add HBAC Service Groups 2019-01-17T11:03:23Z DEBUG Updating ACI for managed permission: System: Add HBAC Service Groups 2019-01-17T11:03:23Z DEBUG Adding ACI u'(targetfilter = "(objectclass=ipahbacservicegroup)")(version 3.0;acl "permission:System: Add HBAC Service Groups";allow (add) groupdn = "ldap:///cn=System: Add HBAC Service Groups,cn=permissions,cn=pbac,dc=local";)' to cn=hbacservicegroups,cn=hbac,dc=local 2019-01-17T11:03:23Z DEBUG Legacy permission Delete HBAC service groups not found 2019-01-17T11:03:23Z DEBUG Updating managed permission: System: Delete HBAC Service Groups 2019-01-17T11:03:23Z DEBUG Updating ACI for managed permission: System: Delete HBAC Service Groups 2019-01-17T11:03:23Z DEBUG Adding ACI u'(targetfilter = "(objectclass=ipahbacservicegroup)")(version 3.0;acl "permission:System: Delete HBAC Service Groups";allow (delete) groupdn = "ldap:///cn=System: Delete HBAC Service Groups,cn=permissions,cn=pbac,dc=local";)' to cn=hbacservicegroups,cn=hbac,dc=local 2019-01-17T11:03:23Z DEBUG Legacy permission Manage HBAC service group membership not found 2019-01-17T11:03:23Z DEBUG Updating managed permission: System: Manage HBAC Service Group Membership 2019-01-17T11:03:23Z DEBUG Updating ACI for managed permission: System: Manage HBAC Service Group Membership 2019-01-17T11:03:23Z DEBUG Adding ACI u'(targetattr = "member")(targetfilter = "(objectclass=ipahbacservicegroup)")(version 3.0;acl "permission:System: Manage HBAC Service Group Membership";allow (write) groupdn = "ldap:///cn=System: Manage HBAC Service Group Membership,cn=permissions,cn=pbac,dc=local";)' to cn=hbacservicegroups,cn=hbac,dc=local 2019-01-17T11:03:23Z DEBUG Updating managed permission: System: Read HBAC Service Groups 2019-01-17T11:03:23Z DEBUG Updating ACI for managed permission: System: Read HBAC Service Groups 2019-01-17T11:03:23Z DEBUG Adding ACI u'(targetattr = "businesscategory || cn || createtimestamp || description || entryusn || ipauniqueid || member || memberhost || memberuser || modifytimestamp || o || objectclass || ou || owner || seealso")(targetfilter = "(objectclass=ipahbacservicegroup)")(version 3.0;acl "permission:System: Read HBAC Service Groups";allow (compare,read,search) userdn = "ldap:///all";)' to cn=hbacservicegroups,cn=hbac,dc=local 2019-01-17T11:03:23Z DEBUG Updating managed permissions for host 2019-01-17T11:03:23Z DEBUG Legacy permission Add Hosts not found 2019-01-17T11:03:23Z DEBUG Updating managed permission: System: Add Hosts 2019-01-17T11:03:23Z DEBUG Updating ACI for managed permission: System: Add Hosts 2019-01-17T11:03:23Z DEBUG Adding ACI u'(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Add Hosts";allow (add) groupdn = "ldap:///cn=System: Add Hosts,cn=permissions,cn=pbac,dc=local";)' to cn=computers,cn=accounts,dc=local 2019-01-17T11:03:23Z DEBUG Legacy permission Add krbPrincipalName to a host not found 2019-01-17T11:03:23Z DEBUG Updating managed permission: System: Add krbPrincipalName to a Host 2019-01-17T11:03:23Z DEBUG Updating ACI for managed permission: System: Add krbPrincipalName to a Host 2019-01-17T11:03:23Z DEBUG Adding ACI u'(targetattr = "krbprincipalname")(targetfilter = "(&(!(krbprincipalname=*))(objectclass=ipahost))")(version 3.0;acl "permission:System: Add krbPrincipalName to a Host";allow (write) groupdn = "ldap:///cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=local";)' to cn=computers,cn=accounts,dc=local 2019-01-17T11:03:23Z DEBUG Legacy permission Enroll a host not found 2019-01-17T11:03:23Z DEBUG Updating managed permission: System: Enroll a Host 2019-01-17T11:03:23Z DEBUG Updating ACI for managed permission: System: Enroll a Host 2019-01-17T11:03:23Z DEBUG Adding ACI u'(targetattr = "enrolledby || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Enroll a Host";allow (write) groupdn = "ldap:///cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=local";)' to cn=computers,cn=accounts,dc=local 2019-01-17T11:03:23Z DEBUG Updating managed permission: System: Manage Host Certificates 2019-01-17T11:03:23Z DEBUG Updating ACI for managed permission: System: Manage Host Certificates 2019-01-17T11:03:23Z DEBUG Adding ACI u'(targetattr = "usercertificate")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Certificates";allow (write) groupdn = "ldap:///cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=local";)' to cn=computers,cn=accounts,dc=local 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Manage Host Enrollment Password 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Manage Host Enrollment Password 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetattr = "userpassword")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Enrollment Password";allow (write) groupdn = "ldap:///cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=local";)' to cn=computers,cn=accounts,dc=local 2019-01-17T11:03:24Z DEBUG Legacy permission Manage host keytab not found 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Manage Host Keytab 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Manage Host Keytab 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(&(!(memberOf=cn=ipaservers,cn=hostgroups,cn=accounts,dc=local))(objectclass=ipahost))")(version 3.0;acl "permission:System: Manage Host Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=local";)' to cn=computers,cn=accounts,dc=local 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Manage Host Keytab Permissions 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Manage Host Keytab Permissions 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Host Keytab Permissions,cn=permissions,cn=pbac,dc=local";)' to cn=computers,cn=accounts,dc=local 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Manage Host Principals 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Manage Host Principals 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Principals";allow (write) groupdn = "ldap:///cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=local";)' to cn=computers,cn=accounts,dc=local 2019-01-17T11:03:24Z DEBUG Legacy permission Manage Host SSH Public Keys not found 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Manage Host SSH Public Keys 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Manage Host SSH Public Keys 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetattr = "ipasshpubkey")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host SSH Public Keys";allow (write) groupdn = "ldap:///cn=System: Manage Host SSH Public Keys,cn=permissions,cn=pbac,dc=local";)' to cn=computers,cn=accounts,dc=local 2019-01-17T11:03:24Z DEBUG Legacy permission Modify Hosts not found 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Modify Hosts 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Modify Hosts 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetattr = "description || ipaassignedidview || krbprincipalauthind || l || macaddress || nshardwareplatform || nshostlocation || nsosversion || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Modify Hosts";allow (write) groupdn = "ldap:///cn=System: Modify Hosts,cn=permissions,cn=pbac,dc=local";)' to cn=computers,cn=accounts,dc=local 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Read Host Compat Tree 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Read Host Compat Tree 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=local")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)' to dc=local 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Read Host Membership 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Read Host Membership 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetattr = "memberof")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Host Membership";allow (compare,read,search) userdn = "ldap:///all";)' to cn=computers,cn=accounts,dc=local 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Read Hosts 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Read Hosts 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetattr = "cn || createtimestamp || description || enrolledby || entryusn || fqdn || ipaassignedidview || ipaclientversion || ipakrbauthzdata || ipasshpubkey || ipauniqueid || krbcanonicalname || krblastpwdchange || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || l || macaddress || managedby || modifytimestamp || nshardwareplatform || nshostlocation || nsosversion || objectclass || serverhostname || usercertificate || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Hosts";allow (compare,read,search) userdn = "ldap:///all";)' to cn=computers,cn=accounts,dc=local 2019-01-17T11:03:24Z DEBUG Legacy permission Remove Hosts not found 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Remove Hosts 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Remove Hosts 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Remove Hosts";allow (delete) groupdn = "ldap:///cn=System: Remove Hosts,cn=permissions,cn=pbac,dc=local";)' to cn=computers,cn=accounts,dc=local 2019-01-17T11:03:24Z DEBUG Updating managed permissions for hostgroup 2019-01-17T11:03:24Z DEBUG Legacy permission Add Hostgroups not found 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Add Hostgroups 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Add Hostgroups 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Add Hostgroups";allow (add) groupdn = "ldap:///cn=System: Add Hostgroups,cn=permissions,cn=pbac,dc=local";)' to cn=hostgroups,cn=accounts,dc=local 2019-01-17T11:03:24Z DEBUG Legacy permission Modify Hostgroup membership not found 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Modify Hostgroup Membership 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Modify Hostgroup Membership 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetattr = "member")(targetfilter = "(&(!(cn=ipaservers))(objectclass=ipahostgroup))")(version 3.0;acl "permission:System: Modify Hostgroup Membership";allow (write) groupdn = "ldap:///cn=System: Modify Hostgroup Membership,cn=permissions,cn=pbac,dc=local";)' to cn=hostgroups,cn=accounts,dc=local 2019-01-17T11:03:24Z DEBUG Legacy permission Modify Hostgroups not found 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Modify Hostgroups 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Modify Hostgroups 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetattr = "cn || description")(targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Modify Hostgroups";allow (write) groupdn = "ldap:///cn=System: Modify Hostgroups,cn=permissions,cn=pbac,dc=local";)' to cn=hostgroups,cn=accounts,dc=local 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Read Hostgroup Membership 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Read Hostgroup Membership 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetattr = "member || memberhost || memberof || memberuser")(targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Read Hostgroup Membership";allow (compare,read,search) userdn = "ldap:///all";)' to cn=hostgroups,cn=accounts,dc=local 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Read Hostgroups 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Read Hostgroups 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetattr = "businesscategory || cn || createtimestamp || description || entryusn || ipauniqueid || modifytimestamp || o || objectclass || ou || owner || seealso")(targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Read Hostgroups";allow (compare,read,search) userdn = "ldap:///all";)' to cn=hostgroups,cn=accounts,dc=local 2019-01-17T11:03:24Z DEBUG Legacy permission Remove Hostgroups not found 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Remove Hostgroups 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Remove Hostgroups 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Remove Hostgroups";allow (delete) groupdn = "ldap:///cn=System: Remove Hostgroups,cn=permissions,cn=pbac,dc=local";)' to cn=hostgroups,cn=accounts,dc=local 2019-01-17T11:03:24Z DEBUG Updating managed permissions for idoverridegroup 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Read Group ID Overrides 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Read Group ID Overrides 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetattr = "cn || createtimestamp || description || entryusn || gidnumber || ipaanchoruuid || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaGroupOverride)")(version 3.0;acl "permission:System: Read Group ID Overrides";allow (compare,read,search) userdn = "ldap:///all";)' to cn=views,cn=accounts,dc=local 2019-01-17T11:03:24Z DEBUG Updating managed permissions for idoverrideuser 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Read User ID Overrides 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Read User ID Overrides 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetattr = "createtimestamp || description || entryusn || gecos || gidnumber || homedirectory || ipaanchoruuid || ipaoriginaluid || ipasshpubkey || loginshell || modifytimestamp || objectclass || uid || uidnumber || usercertificate")(targetfilter = "(objectclass=ipaUserOverride)")(version 3.0;acl "permission:System: Read User ID Overrides";allow (compare,read,search) userdn = "ldap:///all";)' to cn=views,cn=accounts,dc=local 2019-01-17T11:03:24Z DEBUG Updating managed permissions for idrange 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Read ID Ranges 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Read ID Ranges 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetattr = "cn || createtimestamp || entryusn || ipabaseid || ipabaserid || ipaidrangesize || ipanttrusteddomainsid || iparangetype || ipasecondarybaserid || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaidrange)")(version 3.0;acl "permission:System: Read ID Ranges";allow (compare,read,search) userdn = "ldap:///all";)' to cn=ranges,cn=etc,dc=local 2019-01-17T11:03:24Z DEBUG Updating managed permissions for idview 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Read ID Views 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Read ID Views 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetattr = "cn || createtimestamp || description || entryusn || ipadomainresolutionorder || modifytimestamp || objectclass")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Read ID Views";allow (compare,read,search) userdn = "ldap:///all";)' to cn=views,cn=accounts,dc=local 2019-01-17T11:03:24Z DEBUG Updating managed permissions for krbtpolicy 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Read Default Kerberos Ticket Policy 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Read Default Kerberos Ticket Policy 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetattr = "createtimestamp || entryusn || krbdefaultencsalttypes || krbmaxrenewableage || krbmaxticketlife || krbsupportedencsalttypes || modifytimestamp || objectclass")(targetfilter = "(objectclass=krbticketpolicyaux)")(version 3.0;acl "permission:System: Read Default Kerberos Ticket Policy";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Default Kerberos Ticket Policy,cn=permissions,cn=pbac,dc=local";)' to cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Read User Kerberos Ticket Policy 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Read User Kerberos Ticket Policy 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetattr = "krbmaxrenewableage || krbmaxticketlife")(targetfilter = "(objectclass=krbticketpolicyaux)")(version 3.0;acl "permission:System: Read User Kerberos Ticket Policy";allow (compare,read,search) groupdn = "ldap:///cn=System: Read User Kerberos Ticket Policy,cn=permissions,cn=pbac,dc=local";)' to cn=users,cn=accounts,dc=local 2019-01-17T11:03:24Z DEBUG Updating managed permissions for location 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Add IPA Locations 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Add IPA Locations 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetfilter = "(objectclass=ipaLocationObject)")(version 3.0;acl "permission:System: Add IPA Locations";allow (add) groupdn = "ldap:///cn=System: Add IPA Locations,cn=permissions,cn=pbac,dc=local";)' to cn=locations,cn=etc,dc=local 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Modify IPA Locations 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Modify IPA Locations 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetattr = "description")(targetfilter = "(objectclass=ipaLocationObject)")(version 3.0;acl "permission:System: Modify IPA Locations";allow (write) groupdn = "ldap:///cn=System: Modify IPA Locations,cn=permissions,cn=pbac,dc=local";)' to cn=locations,cn=etc,dc=local 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Read IPA Locations 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Read IPA Locations 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetattr = "createtimestamp || description || entryusn || idnsname || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaLocationObject)")(version 3.0;acl "permission:System: Read IPA Locations";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Locations,cn=permissions,cn=pbac,dc=local";)' to cn=locations,cn=etc,dc=local 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Remove IPA Locations 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Remove IPA Locations 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetfilter = "(objectclass=ipaLocationObject)")(version 3.0;acl "permission:System: Remove IPA Locations";allow (delete) groupdn = "ldap:///cn=System: Remove IPA Locations,cn=permissions,cn=pbac,dc=local";)' to cn=locations,cn=etc,dc=local 2019-01-17T11:03:24Z DEBUG Updating managed permissions for netgroup 2019-01-17T11:03:24Z DEBUG Legacy permission Add netgroups not found 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Add Netgroups 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Add Netgroups 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Add Netgroups";allow (add) groupdn = "ldap:///cn=System: Add Netgroups,cn=permissions,cn=pbac,dc=local";)' to cn=ng,cn=alt,dc=local 2019-01-17T11:03:24Z DEBUG Legacy permission Modify netgroup membership not found 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Modify Netgroup Membership 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Modify Netgroup Membership 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetattr = "externalhost || member || memberhost || memberuser")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Modify Netgroup Membership";allow (write) groupdn = "ldap:///cn=System: Modify Netgroup Membership,cn=permissions,cn=pbac,dc=local";)' to cn=ng,cn=alt,dc=local 2019-01-17T11:03:24Z DEBUG Legacy permission Modify netgroups not found 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Modify Netgroups 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Modify Netgroups 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetattr = "description")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Modify Netgroups";allow (write) groupdn = "ldap:///cn=System: Modify Netgroups,cn=permissions,cn=pbac,dc=local";)' to cn=ng,cn=alt,dc=local 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Read Netgroup Compat Tree 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Read Netgroup Compat Tree 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=local")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)' to dc=local 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Read Netgroup Membership 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Read Netgroup Membership 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetattr = "createtimestamp || entryusn || externalhost || member || memberhost || memberof || memberuser || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Read Netgroup Membership";allow (compare,read,search) userdn = "ldap:///all";)' to cn=ng,cn=alt,dc=local 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Read Netgroups 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Read Netgroups 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetattr = "cn || createtimestamp || description || entryusn || hostcategory || ipaenabledflag || ipauniqueid || modifytimestamp || nisdomainname || objectclass || usercategory")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Read Netgroups";allow (compare,read,search) userdn = "ldap:///all";)' to cn=ng,cn=alt,dc=local 2019-01-17T11:03:24Z DEBUG Legacy permission Remove netgroups not found 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Remove Netgroups 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Remove Netgroups 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Remove Netgroups";allow (delete) groupdn = "ldap:///cn=System: Remove Netgroups,cn=permissions,cn=pbac,dc=local";)' to cn=ng,cn=alt,dc=local 2019-01-17T11:03:24Z DEBUG Updating managed permissions for otpconfig 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Read OTP Configuration 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Read OTP Configuration 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetattr = "cn || ipatokenhotpauthwindow || ipatokenhotpsyncwindow || ipatokentotpauthwindow || ipatokentotpsyncwindow")(targetfilter = "(objectclass=ipatokenotpconfig)")(version 3.0;acl "permission:System: Read OTP Configuration";allow (compare,read,search) userdn = "ldap:///all";)' to cn=otp,cn=etc,dc=local 2019-01-17T11:03:24Z DEBUG Updating managed permissions for permission 2019-01-17T11:03:24Z DEBUG Legacy permission Modify privilege membership not found 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Modify Privilege Membership 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Modify Privilege Membership 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetattr = "member")(targetfilter = "(objectclass=ipapermission)")(version 3.0;acl "permission:System: Modify Privilege Membership";allow (write) groupdn = "ldap:///cn=System: Modify Privilege Membership,cn=permissions,cn=pbac,dc=local";)' to cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Read ACIs 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Read ACIs 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=local";)' to dc=local 2019-01-17T11:03:24Z DEBUG Updating managed permission: System: Read Permissions 2019-01-17T11:03:24Z DEBUG Updating ACI for managed permission: System: Read Permissions 2019-01-17T11:03:24Z DEBUG Adding ACI u'(targetattr = "businesscategory || cn || createtimestamp || description || entryusn || ipapermbindruletype || ipapermdefaultattr || ipapermexcludedattr || ipapermincludedattr || ipapermissiontype || ipapermlocation || ipapermright || ipapermtarget || ipapermtargetfilter || member || memberhost || memberof || memberuser || modifytimestamp || o || objectclass || ou || owner || seealso")(targetfilter = "(objectclass=ipapermission)")(version 3.0;acl "permission:System: Read Permissions";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Permissions,cn=permissions,cn=pbac,dc=local";)' to cn=permissions,cn=pbac,dc=local 2019-01-17T11:03:24Z DEBUG Updating managed permissions for privilege 2019-01-17T11:03:25Z DEBUG Updating managed permission: System: Add Privileges 2019-01-17T11:03:25Z DEBUG Updating ACI for managed permission: System: Add Privileges 2019-01-17T11:03:25Z DEBUG Adding ACI u'(targetfilter = "(objectclass=groupofnames)")(version 3.0;acl "permission:System: Add Privileges";allow (add) groupdn = "ldap:///cn=System: Add Privileges,cn=permissions,cn=pbac,dc=local";)' to cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:25Z DEBUG Updating managed permission: System: Modify Privileges 2019-01-17T11:03:25Z DEBUG Updating ACI for managed permission: System: Modify Privileges 2019-01-17T11:03:25Z DEBUG Adding ACI u'(targetattr = "businesscategory || cn || description || o || ou || owner || seealso")(targetfilter = "(objectclass=groupofnames)")(version 3.0;acl "permission:System: Modify Privileges";allow (write) groupdn = "ldap:///cn=System: Modify Privileges,cn=permissions,cn=pbac,dc=local";)' to cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:25Z DEBUG Updating managed permission: System: Read Privileges 2019-01-17T11:03:25Z DEBUG Updating ACI for managed permission: System: Read Privileges 2019-01-17T11:03:25Z DEBUG Adding ACI u'(targetattr = "businesscategory || cn || createtimestamp || description || entryusn || member || memberhost || memberof || memberuser || modifytimestamp || o || objectclass || ou || owner || seealso")(targetfilter = "(objectclass=groupofnames)")(version 3.0;acl "permission:System: Read Privileges";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Privileges,cn=permissions,cn=pbac,dc=local";)' to cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:25Z DEBUG Updating managed permission: System: Remove Privileges 2019-01-17T11:03:25Z DEBUG Updating ACI for managed permission: System: Remove Privileges 2019-01-17T11:03:25Z DEBUG Adding ACI u'(targetfilter = "(objectclass=groupofnames)")(version 3.0;acl "permission:System: Remove Privileges";allow (delete) groupdn = "ldap:///cn=System: Remove Privileges,cn=permissions,cn=pbac,dc=local";)' to cn=privileges,cn=pbac,dc=local 2019-01-17T11:03:25Z DEBUG Updating managed permissions for pwpolicy 2019-01-17T11:03:25Z DEBUG Legacy permission Add Group Password Policy not found 2019-01-17T11:03:25Z DEBUG Updating managed permission: System: Add Group Password Policy 2019-01-17T11:03:25Z DEBUG Updating ACI for managed permission: System: Add Group Password Policy 2019-01-17T11:03:25Z DEBUG Adding ACI u'(targetfilter = "(objectclass=krbpwdpolicy)")(version 3.0;acl "permission:System: Add Group Password Policy";allow (add) groupdn = "ldap:///cn=System: Add Group Password Policy,cn=permissions,cn=pbac,dc=local";)' to cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:03:25Z DEBUG Legacy permission Delete Group Password Policy not found 2019-01-17T11:03:25Z DEBUG Updating managed permission: System: Delete Group Password Policy 2019-01-17T11:03:25Z DEBUG Updating ACI for managed permission: System: Delete Group Password Policy 2019-01-17T11:03:25Z DEBUG Adding ACI u'(targetfilter = "(objectclass=krbpwdpolicy)")(version 3.0;acl "permission:System: Delete Group Password Policy";allow (delete) groupdn = "ldap:///cn=System: Delete Group Password Policy,cn=permissions,cn=pbac,dc=local";)' to cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:03:25Z DEBUG Legacy permission Modify Group Password Policy not found 2019-01-17T11:03:25Z DEBUG Updating managed permission: System: Modify Group Password Policy 2019-01-17T11:03:25Z DEBUG Updating ACI for managed permission: System: Modify Group Password Policy 2019-01-17T11:03:25Z DEBUG Adding ACI u'(targetattr = "krbmaxpwdlife || krbminpwdlife || krbpwdfailurecountinterval || krbpwdhistorylength || krbpwdlockoutduration || krbpwdmaxfailure || krbpwdmindiffchars || krbpwdminlength")(targetfilter = "(objectclass=krbpwdpolicy)")(version 3.0;acl "permission:System: Modify Group Password Policy";allow (write) groupdn = "ldap:///cn=System: Modify Group Password Policy,cn=permissions,cn=pbac,dc=local";)' to cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:03:25Z DEBUG Updating managed permission: System: Read Group Password Policy 2019-01-17T11:03:25Z DEBUG Updating ACI for managed permission: System: Read Group Password Policy 2019-01-17T11:03:25Z DEBUG Adding ACI u'(targetattr = "cn || cospriority || createtimestamp || entryusn || krbmaxpwdlife || krbminpwdlife || krbpwdfailurecountinterval || krbpwdhistorylength || krbpwdlockoutduration || krbpwdmaxfailure || krbpwdmindiffchars || krbpwdminlength || modifytimestamp || objectclass")(targetfilter = "(objectclass=krbpwdpolicy)")(version 3.0;acl "permission:System: Read Group Password Policy";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Group Password Policy,cn=permissions,cn=pbac,dc=local";)' to cn=LOCAL,cn=kerberos,dc=local 2019-01-17T11:03:25Z DEBUG Updating managed permissions for realmdomains 2019-01-17T11:03:25Z DEBUG Updating managed permission: System: Modify Realm Domains 2019-01-17T11:03:25Z DEBUG Updating ACI for managed permission: System: Modify Realm Domains 2019-01-17T11:03:25Z DEBUG Adding ACI u'(targetattr = "associateddomain")(targetfilter = "(objectclass=domainrelatedobject)")(version 3.0;acl "permission:System: Modify Realm Domains";allow (write) groupdn = "ldap:///cn=System: Modify Realm Domains,cn=permissions,cn=pbac,dc=local";)' to cn=Realm Domains,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:25Z DEBUG Updating managed permission: System: Read Realm Domains 2019-01-17T11:03:25Z DEBUG Updating ACI for managed permission: System: Read Realm Domains 2019-01-17T11:03:25Z DEBUG Adding ACI u'(targetattr = "associateddomain || cn || createtimestamp || entryusn || modifytimestamp || objectclass")(targetfilter = "(objectclass=domainrelatedobject)")(version 3.0;acl "permission:System: Read Realm Domains";allow (compare,read,search) userdn = "ldap:///all";)' to cn=Realm Domains,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:25Z DEBUG Updating managed permissions for role 2019-01-17T11:03:25Z DEBUG Legacy permission Add Roles not found 2019-01-17T11:03:25Z DEBUG Updating managed permission: System: Add Roles 2019-01-17T11:03:25Z DEBUG Updating ACI for managed permission: System: Add Roles 2019-01-17T11:03:25Z DEBUG Adding ACI u'(targetfilter = "(objectclass=groupofnames)")(version 3.0;acl "permission:System: Add Roles";allow (add) groupdn = "ldap:///cn=System: Add Roles,cn=permissions,cn=pbac,dc=local";)' to cn=roles,cn=accounts,dc=local 2019-01-17T11:03:25Z DEBUG Legacy permission Modify Role membership not found 2019-01-17T11:03:25Z DEBUG Updating managed permission: System: Modify Role Membership 2019-01-17T11:03:25Z DEBUG Updating ACI for managed permission: System: Modify Role Membership 2019-01-17T11:03:25Z DEBUG Adding ACI u'(targetattr = "member")(targetfilter = "(objectclass=groupofnames)")(version 3.0;acl "permission:System: Modify Role Membership";allow (write) groupdn = "ldap:///cn=System: Modify Role Membership,cn=permissions,cn=pbac,dc=local";)' to cn=roles,cn=accounts,dc=local 2019-01-17T11:03:25Z DEBUG Legacy permission Modify Roles not found 2019-01-17T11:03:25Z DEBUG Updating managed permission: System: Modify Roles 2019-01-17T11:03:25Z DEBUG Updating ACI for managed permission: System: Modify Roles 2019-01-17T11:03:25Z DEBUG Adding ACI u'(targetattr = "cn || description")(targetfilter = "(objectclass=groupofnames)")(version 3.0;acl "permission:System: Modify Roles";allow (write) groupdn = "ldap:///cn=System: Modify Roles,cn=permissions,cn=pbac,dc=local";)' to cn=roles,cn=accounts,dc=local 2019-01-17T11:03:25Z DEBUG Updating managed permission: System: Read Roles 2019-01-17T11:03:25Z DEBUG Updating ACI for managed permission: System: Read Roles 2019-01-17T11:03:25Z DEBUG Adding ACI u'(targetattr = "businesscategory || cn || createtimestamp || description || entryusn || member || memberhost || memberof || memberuser || modifytimestamp || o || objectclass || ou || owner || seealso")(targetfilter = "(objectclass=groupofnames)")(version 3.0;acl "permission:System: Read Roles";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Roles,cn=permissions,cn=pbac,dc=local";)' to cn=roles,cn=accounts,dc=local 2019-01-17T11:03:25Z DEBUG Legacy permission Remove Roles not found 2019-01-17T11:03:25Z DEBUG Updating managed permission: System: Remove Roles 2019-01-17T11:03:25Z DEBUG Updating ACI for managed permission: System: Remove Roles 2019-01-17T11:03:25Z DEBUG Adding ACI u'(targetfilter = "(objectclass=groupofnames)")(version 3.0;acl "permission:System: Remove Roles";allow (delete) groupdn = "ldap:///cn=System: Remove Roles,cn=permissions,cn=pbac,dc=local";)' to cn=roles,cn=accounts,dc=local 2019-01-17T11:03:25Z DEBUG Updating managed permissions for selinuxusermap 2019-01-17T11:03:25Z DEBUG Legacy permission Add SELinux User Maps not found 2019-01-17T11:03:25Z DEBUG Updating managed permission: System: Add SELinux User Maps 2019-01-17T11:03:25Z DEBUG Updating ACI for managed permission: System: Add SELinux User Maps 2019-01-17T11:03:25Z DEBUG Adding ACI u'(targetfilter = "(objectclass=ipaselinuxusermap)")(version 3.0;acl "permission:System: Add SELinux User Maps";allow (add) groupdn = "ldap:///cn=System: Add SELinux User Maps,cn=permissions,cn=pbac,dc=local";)' to cn=usermap,cn=selinux,dc=local 2019-01-17T11:03:25Z DEBUG Legacy permission Modify SELinux User Maps not found 2019-01-17T11:03:25Z DEBUG Updating managed permission: System: Modify SELinux User Maps 2019-01-17T11:03:25Z DEBUG Updating ACI for managed permission: System: Modify SELinux User Maps 2019-01-17T11:03:25Z DEBUG Adding ACI u'(targetattr = "cn || ipaenabledflag || ipaselinuxuser || memberhost || memberuser || seealso")(targetfilter = "(objectclass=ipaselinuxusermap)")(version 3.0;acl "permission:System: Modify SELinux User Maps";allow (write) groupdn = "ldap:///cn=System: Modify SELinux User Maps,cn=permissions,cn=pbac,dc=local";)' to cn=usermap,cn=selinux,dc=local 2019-01-17T11:03:25Z DEBUG Updating managed permission: System: Read SELinux User Maps 2019-01-17T11:03:25Z DEBUG Updating ACI for managed permission: System: Read SELinux User Maps 2019-01-17T11:03:25Z DEBUG Adding ACI u'(targetattr = "accesstime || cn || createtimestamp || description || entryusn || hostcategory || ipaenabledflag || ipaselinuxuser || ipauniqueid || member || memberhost || memberuser || modifytimestamp || objectclass || seealso || usercategory")(targetfilter = "(objectclass=ipaselinuxusermap)")(version 3.0;acl "permission:System: Read SELinux User Maps";allow (compare,read,search) userdn = "ldap:///all";)' to cn=usermap,cn=selinux,dc=local 2019-01-17T11:03:25Z DEBUG Legacy permission Remove SELinux User Maps not found 2019-01-17T11:03:25Z DEBUG Updating managed permission: System: Remove SELinux User Maps 2019-01-17T11:03:25Z DEBUG Updating ACI for managed permission: System: Remove SELinux User Maps 2019-01-17T11:03:25Z DEBUG Adding ACI u'(targetfilter = "(objectclass=ipaselinuxusermap)")(version 3.0;acl "permission:System: Remove SELinux User Maps";allow (delete) groupdn = "ldap:///cn=System: Remove SELinux User Maps,cn=permissions,cn=pbac,dc=local";)' to cn=usermap,cn=selinux,dc=local 2019-01-17T11:03:25Z DEBUG Updating managed permissions for server 2019-01-17T11:03:25Z DEBUG Updating managed permission: System: Read Locations of IPA Servers 2019-01-17T11:03:25Z DEBUG Updating ACI for managed permission: System: Read Locations of IPA Servers 2019-01-17T11:03:25Z DEBUG Adding ACI u'(targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=local";)' to cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:25Z DEBUG Updating managed permission: System: Read Status of Services on IPA Servers 2019-01-17T11:03:25Z DEBUG Updating ACI for managed permission: System: Read Status of Services on IPA Servers 2019-01-17T11:03:25Z DEBUG Adding ACI u'(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=local";)' to cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:25Z DEBUG Updating managed permissions for service 2019-01-17T11:03:25Z DEBUG Legacy permission Add Services not found 2019-01-17T11:03:25Z DEBUG Updating managed permission: System: Add Services 2019-01-17T11:03:25Z DEBUG Updating ACI for managed permission: System: Add Services 2019-01-17T11:03:25Z DEBUG Adding ACI u'(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Add Services";allow (add) groupdn = "ldap:///cn=System: Add Services,cn=permissions,cn=pbac,dc=local";)' to cn=services,cn=accounts,dc=local 2019-01-17T11:03:25Z DEBUG Legacy permission Manage service keytab not found 2019-01-17T11:03:25Z DEBUG Updating managed permission: System: Manage Service Keytab 2019-01-17T11:03:25Z DEBUG Updating ACI for managed permission: System: Manage Service Keytab 2019-01-17T11:03:25Z DEBUG Adding ACI u'(targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Service Keytab,cn=permissions,cn=pbac,dc=local";)' to cn=services,cn=accounts,dc=local 2019-01-17T11:03:25Z DEBUG Updating managed permission: System: Manage Service Keytab Permissions 2019-01-17T11:03:26Z DEBUG Updating ACI for managed permission: System: Manage Service Keytab Permissions 2019-01-17T11:03:26Z DEBUG Adding ACI u'(targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Service Keytab Permissions,cn=permissions,cn=pbac,dc=local";)' to cn=services,cn=accounts,dc=local 2019-01-17T11:03:26Z DEBUG Updating managed permission: System: Manage Service Principals 2019-01-17T11:03:26Z DEBUG Updating ACI for managed permission: System: Manage Service Principals 2019-01-17T11:03:26Z DEBUG Adding ACI u'(targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Principals";allow (write) groupdn = "ldap:///cn=System: Manage Service Principals,cn=permissions,cn=pbac,dc=local";)' to cn=services,cn=accounts,dc=local 2019-01-17T11:03:26Z DEBUG Legacy permission Modify Services not found 2019-01-17T11:03:26Z DEBUG Updating managed permission: System: Modify Services 2019-01-17T11:03:26Z DEBUG Updating ACI for managed permission: System: Modify Services 2019-01-17T11:03:26Z DEBUG Adding ACI u'(targetattr = "krbprincipalauthind || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Modify Services";allow (write) groupdn = "ldap:///cn=System: Modify Services,cn=permissions,cn=pbac,dc=local";)' to cn=services,cn=accounts,dc=local 2019-01-17T11:03:26Z DEBUG Updating managed permission: System: Read Services 2019-01-17T11:03:26Z DEBUG Updating ACI for managed permission: System: Read Services 2019-01-17T11:03:26Z DEBUG Adding ACI u'(targetattr = "createtimestamp || entryusn || ipakrbauthzdata || ipakrbprincipalalias || ipauniqueid || krbcanonicalname || krblastpwdchange || krbobjectreferences || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || managedby || memberof || modifytimestamp || objectclass || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read Services";allow (compare,read,search) userdn = "ldap:///all";)' to cn=services,cn=accounts,dc=local 2019-01-17T11:03:26Z DEBUG Legacy permission Remove Services not found 2019-01-17T11:03:26Z DEBUG Updating managed permission: System: Remove Services 2019-01-17T11:03:26Z DEBUG Updating ACI for managed permission: System: Remove Services 2019-01-17T11:03:26Z DEBUG Adding ACI u'(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Remove Services";allow (delete) groupdn = "ldap:///cn=System: Remove Services,cn=permissions,cn=pbac,dc=local";)' to cn=services,cn=accounts,dc=local 2019-01-17T11:03:26Z DEBUG Updating managed permissions for servicedelegationrule 2019-01-17T11:03:26Z DEBUG Updating managed permission: System: Add Service Delegations 2019-01-17T11:03:26Z DEBUG Updating ACI for managed permission: System: Add Service Delegations 2019-01-17T11:03:26Z DEBUG Adding ACI u'(targetfilter = "(objectclass=groupofprincipals)")(version 3.0;acl "permission:System: Add Service Delegations";allow (add) groupdn = "ldap:///cn=System: Add Service Delegations,cn=permissions,cn=pbac,dc=local";)' to cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:26Z DEBUG Updating managed permission: System: Modify Service Delegation Membership 2019-01-17T11:03:26Z DEBUG Updating ACI for managed permission: System: Modify Service Delegation Membership 2019-01-17T11:03:26Z DEBUG Adding ACI u'(targetattr = "ipaallowedtarget || memberprincipal")(targetfilter = "(objectclass=groupofprincipals)")(version 3.0;acl "permission:System: Modify Service Delegation Membership";allow (write) groupdn = "ldap:///cn=System: Modify Service Delegation Membership,cn=permissions,cn=pbac,dc=local";)' to cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:26Z DEBUG Updating managed permission: System: Read Service Delegations 2019-01-17T11:03:26Z DEBUG Updating ACI for managed permission: System: Read Service Delegations 2019-01-17T11:03:26Z DEBUG Adding ACI u'(targetattr = "cn || createtimestamp || entryusn || ipaallowedtarget || memberprincipal || modifytimestamp || objectclass")(targetfilter = "(objectclass=groupofprincipals)")(version 3.0;acl "permission:System: Read Service Delegations";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Service Delegations,cn=permissions,cn=pbac,dc=local";)' to cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:26Z DEBUG Updating managed permission: System: Remove Service Delegations 2019-01-17T11:03:26Z DEBUG Updating ACI for managed permission: System: Remove Service Delegations 2019-01-17T11:03:26Z DEBUG Adding ACI u'(targetfilter = "(objectclass=groupofprincipals)")(version 3.0;acl "permission:System: Remove Service Delegations";allow (delete) groupdn = "ldap:///cn=System: Remove Service Delegations,cn=permissions,cn=pbac,dc=local";)' to cn=s4u2proxy,cn=etc,dc=local 2019-01-17T11:03:26Z DEBUG Updating managed permissions for servicedelegationtarget 2019-01-17T11:03:26Z DEBUG Updating managed permission: System: Add Service Delegations 2019-01-17T11:03:26Z DEBUG No changes to permission: System: Add Service Delegations 2019-01-17T11:03:26Z DEBUG Updating managed permission: System: Modify Service Delegation Membership 2019-01-17T11:03:26Z DEBUG No changes to permission: System: Modify Service Delegation Membership 2019-01-17T11:03:26Z DEBUG Updating managed permission: System: Read Service Delegations 2019-01-17T11:03:26Z DEBUG No changes to permission: System: Read Service Delegations 2019-01-17T11:03:26Z DEBUG Updating managed permission: System: Remove Service Delegations 2019-01-17T11:03:26Z DEBUG No changes to permission: System: Remove Service Delegations 2019-01-17T11:03:26Z DEBUG Updating managed permissions for stageuser 2019-01-17T11:03:26Z DEBUG Updating managed permission: System: Add Stage User 2019-01-17T11:03:26Z DEBUG Updating ACI for managed permission: System: Add Stage User 2019-01-17T11:03:26Z DEBUG Adding ACI u'(targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=local")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Add Stage User";allow (add) groupdn = "ldap:///cn=System: Add Stage User,cn=permissions,cn=pbac,dc=local";)' to cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:26Z DEBUG Updating managed permission: System: Modify Preserved Users 2019-01-17T11:03:26Z DEBUG Updating ACI for managed permission: System: Modify Preserved Users 2019-01-17T11:03:26Z DEBUG Adding ACI u'(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=local")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify Preserved Users";allow (write) groupdn = "ldap:///cn=System: Modify Preserved Users,cn=permissions,cn=pbac,dc=local";)' to cn=deleted users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:26Z DEBUG Updating managed permission: System: Modify Stage User 2019-01-17T11:03:26Z DEBUG Updating ACI for managed permission: System: Modify Stage User 2019-01-17T11:03:26Z DEBUG Adding ACI u'(targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=local")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Modify Stage User";allow (write) groupdn = "ldap:///cn=System: Modify Stage User,cn=permissions,cn=pbac,dc=local";)' to cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:26Z DEBUG Updating managed permission: System: Modify User RDN 2019-01-17T11:03:26Z DEBUG Updating ACI for managed permission: System: Modify User RDN 2019-01-17T11:03:26Z DEBUG Adding ACI u'(targetattr = "uid")(target = "ldap:///uid=*,cn=users,cn=accounts,dc=local")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify User RDN";allow (write) groupdn = "ldap:///cn=System: Modify User RDN,cn=permissions,cn=pbac,dc=local";)' to cn=users,cn=accounts,dc=local 2019-01-17T11:03:26Z DEBUG Updating managed permission: System: Preserve User 2019-01-17T11:03:26Z DEBUG Updating ACI for managed permission: System: Preserve User 2019-01-17T11:03:26Z DEBUG Adding ACI u'(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=local")(target_from = "ldap:///cn=users,cn=accounts,dc=local")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=local";)' to dc=local 2019-01-17T11:03:26Z DEBUG Updating managed permission: System: Read Preserved Users 2019-01-17T11:03:26Z DEBUG Updating ACI for managed permission: System: Read Preserved Users 2019-01-17T11:03:26Z DEBUG Adding ACI u'(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=local")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read Preserved Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Preserved Users,cn=permissions,cn=pbac,dc=local";)' to cn=deleted users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:26Z DEBUG Updating managed permission: System: Read Stage User password 2019-01-17T11:03:26Z DEBUG Updating ACI for managed permission: System: Read Stage User password 2019-01-17T11:03:26Z DEBUG Adding ACI u'(targetattr = "krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=local")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Read Stage User password";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Stage User password,cn=permissions,cn=pbac,dc=local";)' to cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:26Z DEBUG Updating managed permission: System: Read Stage Users 2019-01-17T11:03:26Z DEBUG Updating ACI for managed permission: System: Read Stage Users 2019-01-17T11:03:26Z DEBUG Adding ACI u'(targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=local")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Read Stage Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Stage Users,cn=permissions,cn=pbac,dc=local";)' to cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:27Z DEBUG Updating managed permission: System: Remove Stage User 2019-01-17T11:03:27Z DEBUG Updating ACI for managed permission: System: Remove Stage User 2019-01-17T11:03:27Z DEBUG Adding ACI u'(targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=local")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove Stage User";allow (delete) groupdn = "ldap:///cn=System: Remove Stage User,cn=permissions,cn=pbac,dc=local";)' to cn=staged users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:27Z DEBUG Updating managed permission: System: Remove preserved User 2019-01-17T11:03:27Z DEBUG Updating ACI for managed permission: System: Remove preserved User 2019-01-17T11:03:27Z DEBUG Adding ACI u'(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=local")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove preserved User";allow (delete) groupdn = "ldap:///cn=System: Remove preserved User,cn=permissions,cn=pbac,dc=local";)' to cn=deleted users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:27Z DEBUG Updating managed permission: System: Reset Preserved User password 2019-01-17T11:03:27Z DEBUG Updating ACI for managed permission: System: Reset Preserved User password 2019-01-17T11:03:27Z DEBUG Adding ACI u'(targetattr = "krblastpwdchange || krbpasswordexpiration || krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=local")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Reset Preserved User password";allow (read,search,write) groupdn = "ldap:///cn=System: Reset Preserved User password,cn=permissions,cn=pbac,dc=local";)' to cn=deleted users,cn=accounts,cn=provisioning,dc=local 2019-01-17T11:03:27Z DEBUG Updating managed permission: System: Undelete User 2019-01-17T11:03:27Z DEBUG Updating ACI for managed permission: System: Undelete User 2019-01-17T11:03:27Z DEBUG Adding ACI u'(target_to = "ldap:///cn=users,cn=accounts,dc=local")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=local")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=local";)' to dc=local 2019-01-17T11:03:27Z DEBUG Updating managed permissions for sudocmd 2019-01-17T11:03:27Z DEBUG Legacy permission Add Sudo command not found 2019-01-17T11:03:27Z DEBUG Updating managed permission: System: Add Sudo Command 2019-01-17T11:03:27Z DEBUG Updating ACI for managed permission: System: Add Sudo Command 2019-01-17T11:03:27Z DEBUG Adding ACI u'(targetfilter = "(objectclass=ipasudocmd)")(version 3.0;acl "permission:System: Add Sudo Command";allow (add) groupdn = "ldap:///cn=System: Add Sudo Command,cn=permissions,cn=pbac,dc=local";)' to cn=sudocmds,cn=sudo,dc=local 2019-01-17T11:03:27Z DEBUG Legacy permission Delete Sudo command not found 2019-01-17T11:03:27Z DEBUG Updating managed permission: System: Delete Sudo Command 2019-01-17T11:03:27Z DEBUG Updating ACI for managed permission: System: Delete Sudo Command 2019-01-17T11:03:27Z DEBUG Adding ACI u'(targetfilter = "(objectclass=ipasudocmd)")(version 3.0;acl "permission:System: Delete Sudo Command";allow (delete) groupdn = "ldap:///cn=System: Delete Sudo Command,cn=permissions,cn=pbac,dc=local";)' to cn=sudocmds,cn=sudo,dc=local 2019-01-17T11:03:27Z DEBUG Legacy permission Modify Sudo command not found 2019-01-17T11:03:27Z DEBUG Updating managed permission: System: Modify Sudo Command 2019-01-17T11:03:27Z DEBUG Updating ACI for managed permission: System: Modify Sudo Command 2019-01-17T11:03:27Z DEBUG Adding ACI u'(targetattr = "description")(targetfilter = "(objectclass=ipasudocmd)")(version 3.0;acl "permission:System: Modify Sudo Command";allow (write) groupdn = "ldap:///cn=System: Modify Sudo Command,cn=permissions,cn=pbac,dc=local";)' to cn=sudocmds,cn=sudo,dc=local 2019-01-17T11:03:27Z DEBUG Updating managed permission: System: Read Sudo Commands 2019-01-17T11:03:27Z DEBUG Updating ACI for managed permission: System: Read Sudo Commands 2019-01-17T11:03:27Z DEBUG Adding ACI u'(targetattr = "createtimestamp || description || entryusn || ipauniqueid || memberof || modifytimestamp || objectclass || sudocmd")(targetfilter = "(objectclass=ipasudocmd)")(version 3.0;acl "permission:System: Read Sudo Commands";allow (compare,read,search) userdn = "ldap:///all";)' to cn=sudocmds,cn=sudo,dc=local 2019-01-17T11:03:27Z DEBUG Updating managed permissions for sudocmdgroup 2019-01-17T11:03:27Z DEBUG Legacy permission Add Sudo command group not found 2019-01-17T11:03:27Z DEBUG Updating managed permission: System: Add Sudo Command Group 2019-01-17T11:03:27Z DEBUG Updating ACI for managed permission: System: Add Sudo Command Group 2019-01-17T11:03:27Z DEBUG Adding ACI u'(targetfilter = "(objectclass=ipasudocmdgrp)")(version 3.0;acl "permission:System: Add Sudo Command Group";allow (add) groupdn = "ldap:///cn=System: Add Sudo Command Group,cn=permissions,cn=pbac,dc=local";)' to cn=sudocmdgroups,cn=sudo,dc=local 2019-01-17T11:03:27Z DEBUG Legacy permission Delete Sudo command group not found 2019-01-17T11:03:27Z DEBUG Updating managed permission: System: Delete Sudo Command Group 2019-01-17T11:03:27Z DEBUG Updating ACI for managed permission: System: Delete Sudo Command Group 2019-01-17T11:03:27Z DEBUG Adding ACI u'(targetfilter = "(objectclass=ipasudocmdgrp)")(version 3.0;acl "permission:System: Delete Sudo Command Group";allow (delete) groupdn = "ldap:///cn=System: Delete Sudo Command Group,cn=permissions,cn=pbac,dc=local";)' to cn=sudocmdgroups,cn=sudo,dc=local 2019-01-17T11:03:27Z DEBUG Legacy permission Manage Sudo command group membership not found 2019-01-17T11:03:27Z DEBUG Updating managed permission: System: Manage Sudo Command Group Membership 2019-01-17T11:03:27Z DEBUG Updating ACI for managed permission: System: Manage Sudo Command Group Membership 2019-01-17T11:03:27Z DEBUG Adding ACI u'(targetattr = "member")(targetfilter = "(objectclass=ipasudocmdgrp)")(version 3.0;acl "permission:System: Manage Sudo Command Group Membership";allow (write) groupdn = "ldap:///cn=System: Manage Sudo Command Group Membership,cn=permissions,cn=pbac,dc=local";)' to cn=sudocmdgroups,cn=sudo,dc=local 2019-01-17T11:03:27Z DEBUG Updating managed permission: System: Modify Sudo Command Group 2019-01-17T11:03:27Z DEBUG Updating ACI for managed permission: System: Modify Sudo Command Group 2019-01-17T11:03:27Z DEBUG Adding ACI u'(targetattr = "description")(targetfilter = "(objectclass=ipasudocmdgrp)")(version 3.0;acl "permission:System: Modify Sudo Command Group";allow (write) groupdn = "ldap:///cn=System: Modify Sudo Command Group,cn=permissions,cn=pbac,dc=local";)' to cn=sudocmdgroups,cn=sudo,dc=local 2019-01-17T11:03:27Z DEBUG Updating managed permission: System: Read Sudo Command Groups 2019-01-17T11:03:27Z DEBUG Updating ACI for managed permission: System: Read Sudo Command Groups 2019-01-17T11:03:27Z DEBUG Adding ACI u'(targetattr = "businesscategory || cn || createtimestamp || description || entryusn || ipauniqueid || member || memberhost || memberuser || modifytimestamp || o || objectclass || ou || owner || seealso")(targetfilter = "(objectclass=ipasudocmdgrp)")(version 3.0;acl "permission:System: Read Sudo Command Groups";allow (compare,read,search) userdn = "ldap:///all";)' to cn=sudocmdgroups,cn=sudo,dc=local 2019-01-17T11:03:27Z DEBUG Updating managed permissions for sudorule 2019-01-17T11:03:27Z DEBUG Legacy permission Add Sudo rule not found 2019-01-17T11:03:27Z DEBUG Updating managed permission: System: Add Sudo rule 2019-01-17T11:03:27Z DEBUG Updating ACI for managed permission: System: Add Sudo rule 2019-01-17T11:03:27Z DEBUG Adding ACI u'(targetfilter = "(objectclass=ipasudorule)")(version 3.0;acl "permission:System: Add Sudo rule";allow (add) groupdn = "ldap:///cn=System: Add Sudo rule,cn=permissions,cn=pbac,dc=local";)' to cn=sudorules,cn=sudo,dc=local 2019-01-17T11:03:27Z DEBUG Legacy permission Delete Sudo rule not found 2019-01-17T11:03:27Z DEBUG Updating managed permission: System: Delete Sudo rule 2019-01-17T11:03:27Z DEBUG Updating ACI for managed permission: System: Delete Sudo rule 2019-01-17T11:03:27Z DEBUG Adding ACI u'(targetfilter = "(objectclass=ipasudorule)")(version 3.0;acl "permission:System: Delete Sudo rule";allow (delete) groupdn = "ldap:///cn=System: Delete Sudo rule,cn=permissions,cn=pbac,dc=local";)' to cn=sudorules,cn=sudo,dc=local 2019-01-17T11:03:27Z DEBUG Legacy permission Modify Sudo rule not found 2019-01-17T11:03:27Z DEBUG Updating managed permission: System: Modify Sudo rule 2019-01-17T11:03:27Z DEBUG Updating ACI for managed permission: System: Modify Sudo rule 2019-01-17T11:03:27Z DEBUG Adding ACI u'(targetattr = "cmdcategory || description || externalhost || externaluser || hostcategory || hostmask || ipaenabledflag || ipasudoopt || ipasudorunas || ipasudorunasextgroup || ipasudorunasextuser || ipasudorunasextusergroup || ipasudorunasgroup || ipasudorunasgroupcategory || ipasudorunasusercategory || memberallowcmd || memberdenycmd || memberhost || memberuser || sudonotafter || sudonotbefore || sudoorder || usercategory")(targetfilter = "(objectclass=ipasudorule)")(version 3.0;acl "permission:System: Modify Sudo rule";allow (write) groupdn = "ldap:///cn=System: Modify Sudo rule,cn=permissions,cn=pbac,dc=local";)' to cn=sudorules,cn=sudo,dc=local 2019-01-17T11:03:27Z DEBUG Updating managed permission: System: Read Sudo Rules 2019-01-17T11:03:27Z DEBUG Updating ACI for managed permission: System: Read Sudo Rules 2019-01-17T11:03:27Z DEBUG Adding ACI u'(targetattr = "cmdcategory || cn || createtimestamp || description || entryusn || externalhost || externaluser || hostcategory || hostmask || ipaenabledflag || ipasudoopt || ipasudorunas || ipasudorunasextgroup || ipasudorunasextuser || ipasudorunasextusergroup || ipasudorunasgroup || ipasudorunasgroupcategory || ipasudorunasusercategory || ipauniqueid || member || memberallowcmd || memberdenycmd || memberhost || memberuser || modifytimestamp || objectclass || sudonotafter || sudonotbefore || sudoorder || usercategory")(targetfilter = "(objectclass=ipasudorule)")(version 3.0;acl "permission:System: Read Sudo Rules";allow (compare,read,search) userdn = "ldap:///all";)' to cn=sudorules,cn=sudo,dc=local 2019-01-17T11:03:27Z DEBUG Updating managed permission: System: Read Sudoers compat tree 2019-01-17T11:03:27Z DEBUG Updating ACI for managed permission: System: Read Sudoers compat tree 2019-01-17T11:03:27Z DEBUG Adding ACI u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=local")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)' to dc=local 2019-01-17T11:03:27Z DEBUG Updating managed permissions for trust 2019-01-17T11:03:27Z DEBUG Updating managed permission: System: Read Trust Information 2019-01-17T11:03:27Z DEBUG Updating ACI for managed permission: System: Read Trust Information 2019-01-17T11:03:27Z WARNING Unparseable ACI (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";): malformed ACI, match for version and bind rule failed (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) (at cn=trusts,dc=local) 2019-01-17T11:03:27Z DEBUG Adding ACI u'(targetattr = "cn || createtimestamp || entryusn || ipantadditionalsuffixes || ipantflatname || ipantsecurityidentifier || ipantsidblacklistincoming || ipantsidblacklistoutgoing || ipanttrustdirection || ipanttrusteddomainsid || ipanttrustpartner || modifytimestamp || objectclass")(version 3.0;acl "permission:System: Read Trust Information";allow (compare,read,search) userdn = "ldap:///all";)' to cn=trusts,dc=local 2019-01-17T11:03:27Z DEBUG Updating managed permission: System: Read system trust accounts 2019-01-17T11:03:27Z DEBUG Updating ACI for managed permission: System: Read system trust accounts 2019-01-17T11:03:27Z WARNING Unparseable ACI (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";): malformed ACI, match for version and bind rule failed (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) (at cn=trusts,dc=local) 2019-01-17T11:03:27Z DEBUG Adding ACI u'(targetattr = "gidnumber || krbprincipalname || uidnumber")(version 3.0;acl "permission:System: Read system trust accounts";allow (compare,read,search) groupdn = "ldap:///cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=local";)' to cn=trusts,dc=local 2019-01-17T11:03:27Z DEBUG Updating managed permissions for user 2019-01-17T11:03:27Z DEBUG Legacy permission Add user to default group not found 2019-01-17T11:03:27Z DEBUG Updating managed permission: System: Add User to default group 2019-01-17T11:03:27Z DEBUG Updating ACI for managed permission: System: Add User to default group 2019-01-17T11:03:27Z DEBUG Adding ACI u'(targetattr = "member")(target = "ldap:///cn=ipausers,cn=groups,cn=accounts,dc=local")(version 3.0;acl "permission:System: Add User to default group";allow (write) groupdn = "ldap:///cn=System: Add User to default group,cn=permissions,cn=pbac,dc=local";)' to cn=groups,cn=accounts,dc=local 2019-01-17T11:03:28Z DEBUG Legacy permission Add Users not found 2019-01-17T11:03:28Z DEBUG Updating managed permission: System: Add Users 2019-01-17T11:03:28Z DEBUG Updating ACI for managed permission: System: Add Users 2019-01-17T11:03:28Z DEBUG Adding ACI u'(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Add Users";allow (add) groupdn = "ldap:///cn=System: Add Users,cn=permissions,cn=pbac,dc=local";)' to cn=users,cn=accounts,dc=local 2019-01-17T11:03:28Z DEBUG Legacy permission Change a user password not found 2019-01-17T11:03:28Z DEBUG Updating managed permission: System: Change User password 2019-01-17T11:03:28Z DEBUG Updating ACI for managed permission: System: Change User password 2019-01-17T11:03:28Z DEBUG Adding ACI u'(targetattr = "krbpasswordexpiration || krbprincipalkey || passwordhistory || sambalmpassword || sambantpassword || userpassword")(targetfilter = "(&(!(memberOf=cn=admins,cn=groups,cn=accounts,dc=local))(objectclass=posixaccount))")(version 3.0;acl "permission:System: Change User password";allow (write) groupdn = "ldap:///cn=System: Change User password,cn=permissions,cn=pbac,dc=local";)' to cn=users,cn=accounts,dc=local 2019-01-17T11:03:28Z DEBUG Updating managed permission: System: Manage User Certificate Mappings 2019-01-17T11:03:28Z DEBUG Updating ACI for managed permission: System: Manage User Certificate Mappings 2019-01-17T11:03:28Z DEBUG Adding ACI u'(targetattr = "ipacertmapdata || objectclass")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Manage User Certificate Mappings";allow (write) groupdn = "ldap:///cn=System: Manage User Certificate Mappings,cn=permissions,cn=pbac,dc=local";)' to cn=users,cn=accounts,dc=local 2019-01-17T11:03:28Z DEBUG Updating managed permission: System: Manage User Certificates 2019-01-17T11:03:28Z DEBUG Updating ACI for managed permission: System: Manage User Certificates 2019-01-17T11:03:28Z DEBUG Adding ACI u'(targetattr = "usercertificate")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Manage User Certificates";allow (write) groupdn = "ldap:///cn=System: Manage User Certificates,cn=permissions,cn=pbac,dc=local";)' to cn=users,cn=accounts,dc=local 2019-01-17T11:03:28Z DEBUG Updating managed permission: System: Manage User Principals 2019-01-17T11:03:28Z DEBUG Updating ACI for managed permission: System: Manage User Principals 2019-01-17T11:03:28Z DEBUG Adding ACI u'(targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Manage User Principals";allow (write) groupdn = "ldap:///cn=System: Manage User Principals,cn=permissions,cn=pbac,dc=local";)' to cn=users,cn=accounts,dc=local 2019-01-17T11:03:28Z DEBUG Legacy permission Manage User SSH Public Keys not found 2019-01-17T11:03:28Z DEBUG Updating managed permission: System: Manage User SSH Public Keys 2019-01-17T11:03:28Z DEBUG Updating ACI for managed permission: System: Manage User SSH Public Keys 2019-01-17T11:03:28Z DEBUG Adding ACI u'(targetattr = "ipasshpubkey")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Manage User SSH Public Keys";allow (write) groupdn = "ldap:///cn=System: Manage User SSH Public Keys,cn=permissions,cn=pbac,dc=local";)' to cn=users,cn=accounts,dc=local 2019-01-17T11:03:28Z DEBUG Legacy permission Modify Users not found 2019-01-17T11:03:28Z DEBUG Updating managed permission: System: Modify Users 2019-01-17T11:03:28Z DEBUG Updating ACI for managed permission: System: Modify Users 2019-01-17T11:03:28Z DEBUG Adding ACI u'(targetattr = "businesscategory || carlicense || cn || departmentnumber || description || displayname || employeenumber || employeetype || facsimiletelephonenumber || gecos || givenname || homedirectory || homephone || inetuserhttpurl || initials || l || labeleduri || loginshell || mail || manager || mepmanagedentry || mobile || objectclass || ou || pager || postalcode || preferredlanguage || roomnumber || secretary || seealso || sn || st || street || telephonenumber || title || userclass")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify Users";allow (write) groupdn = "ldap:///cn=System: Modify Users,cn=permissions,cn=pbac,dc=local";)' to cn=users,cn=accounts,dc=local 2019-01-17T11:03:28Z DEBUG Updating managed permission: System: Read UPG Definition 2019-01-17T11:03:28Z DEBUG Updating ACI for managed permission: System: Read UPG Definition 2019-01-17T11:03:28Z DEBUG Adding ACI u'(targetattr = "*")(target = "ldap:///cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=local")(version 3.0;acl "permission:System: Read UPG Definition";allow (compare,read,search) groupdn = "ldap:///cn=System: Read UPG Definition,cn=permissions,cn=pbac,dc=local";)' to cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=local 2019-01-17T11:03:28Z DEBUG Updating managed permission: System: Read User Addressbook Attributes 2019-01-17T11:03:28Z DEBUG Updating ACI for managed permission: System: Read User Addressbook Attributes 2019-01-17T11:03:28Z DEBUG Adding ACI u'(targetattr = "audio || businesscategory || carlicense || departmentnumber || destinationindicator || employeenumber || employeetype || facsimiletelephonenumber || homephone || homepostaladdress || inetuserhttpurl || inetuserstatus || internationalisdnnumber || ipacertmapdata || jpegphoto || l || labeleduri || mail || mobile || o || ou || pager || photo || physicaldeliveryofficename || postaladdress || postalcode || postofficebox || preferreddeliverymethod || preferredlanguage || registeredaddress || roomnumber || secretary || seealso || st || street || telephonenumber || teletexterminalidentifier || telexnumber || usercertificate || usersmimecertificate || x121address || x500uniqueidentifier")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Addressbook Attributes";allow (compare,read,search) userdn = "ldap:///all";)' to cn=users,cn=accounts,dc=local 2019-01-17T11:03:28Z DEBUG Updating managed permission: System: Read User Compat Tree 2019-01-17T11:03:28Z DEBUG Updating ACI for managed permission: System: Read User Compat Tree 2019-01-17T11:03:28Z DEBUG Adding ACI u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=local")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)' to dc=local 2019-01-17T11:03:28Z DEBUG Updating managed permission: System: Read User IPA Attributes 2019-01-17T11:03:28Z DEBUG Updating ACI for managed permission: System: Read User IPA Attributes 2019-01-17T11:03:28Z DEBUG Adding ACI u'(targetattr = "ipasshpubkey || ipauniqueid || ipauserauthtype || userclass")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User IPA Attributes";allow (compare,read,search) userdn = "ldap:///all";)' to cn=users,cn=accounts,dc=local 2019-01-17T11:03:28Z DEBUG Updating managed permission: System: Read User Kerberos Attributes 2019-01-17T11:03:28Z DEBUG Updating ACI for managed permission: System: Read User Kerberos Attributes 2019-01-17T11:03:28Z DEBUG Adding ACI u'(targetattr = "krbcanonicalname || krblastpwdchange || krbpasswordexpiration || krbprincipalaliases || krbprincipalexpiration || krbprincipalname || krbprincipaltype || nsaccountlock")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Kerberos Attributes";allow (compare,read,search) userdn = "ldap:///all";)' to cn=users,cn=accounts,dc=local 2019-01-17T11:03:28Z DEBUG Updating managed permission: System: Read User Kerberos Login Attributes 2019-01-17T11:03:28Z DEBUG Updating ACI for managed permission: System: Read User Kerberos Login Attributes 2019-01-17T11:03:28Z DEBUG Adding ACI u'(targetattr = "krblastadminunlock || krblastfailedauth || krblastpwdchange || krblastsuccessfulauth || krbloginfailedcount || krbpwdpolicyreference || krbticketpolicyreference || krbupenabled")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Kerberos Login Attributes";allow (compare,read,search) groupdn = "ldap:///cn=System: Read User Kerberos Login Attributes,cn=permissions,cn=pbac,dc=local";)' to cn=users,cn=accounts,dc=local 2019-01-17T11:03:28Z DEBUG Updating managed permission: System: Read User Membership 2019-01-17T11:03:28Z DEBUG Updating ACI for managed permission: System: Read User Membership 2019-01-17T11:03:28Z DEBUG Adding ACI u'(targetattr = "memberof")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Membership";allow (compare,read,search) userdn = "ldap:///all";)' to cn=users,cn=accounts,dc=local 2019-01-17T11:03:28Z DEBUG Updating managed permission: System: Read User NT Attributes 2019-01-17T11:03:28Z DEBUG Updating ACI for managed permission: System: Read User NT Attributes 2019-01-17T11:03:28Z DEBUG Adding ACI u'(targetattr = "ntuniqueid || ntuseracctexpires || ntusercodepage || ntuserdeleteaccount || ntuserdomainid || ntuserlastlogoff || ntuserlastlogon")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User NT Attributes";allow (compare,read,search) groupdn = "ldap:///cn=System: Read User NT Attributes,cn=permissions,cn=pbac,dc=local";)' to cn=users,cn=accounts,dc=local 2019-01-17T11:03:28Z DEBUG Updating managed permission: System: Read User Standard Attributes 2019-01-17T11:03:28Z DEBUG Updating ACI for managed permission: System: Read User Standard Attributes 2019-01-17T11:03:28Z DEBUG Adding ACI u'(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || initials || ipantsecurityidentifier || loginshell || manager || modifytimestamp || objectclass || sn || title || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Standard Attributes";allow (compare,read,search) userdn = "ldap:///anyone";)' to cn=users,cn=accounts,dc=local 2019-01-17T11:03:28Z DEBUG Updating managed permission: System: Read User Views Compat Tree 2019-01-17T11:03:28Z DEBUG Updating ACI for managed permission: System: Read User Views Compat Tree 2019-01-17T11:03:28Z DEBUG Adding ACI u'(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=local")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)' to dc=local 2019-01-17T11:03:28Z DEBUG Legacy permission Remove Users not found 2019-01-17T11:03:28Z DEBUG Updating managed permission: System: Remove Users 2019-01-17T11:03:28Z DEBUG Updating ACI for managed permission: System: Remove Users 2019-01-17T11:03:28Z DEBUG Adding ACI u'(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Remove Users";allow (delete) groupdn = "ldap:///cn=System: Remove Users,cn=permissions,cn=pbac,dc=local";)' to cn=users,cn=accounts,dc=local 2019-01-17T11:03:28Z DEBUG Legacy permission Unlock user accounts not found 2019-01-17T11:03:28Z DEBUG Updating managed permission: System: Unlock User 2019-01-17T11:03:28Z DEBUG Updating ACI for managed permission: System: Unlock User 2019-01-17T11:03:28Z DEBUG Adding ACI u'(targetattr = "krblastadminunlock || krbloginfailedcount || nsaccountlock")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Unlock User";allow (write) groupdn = "ldap:///cn=System: Unlock User,cn=permissions,cn=pbac,dc=local";)' to cn=users,cn=accounts,dc=local 2019-01-17T11:03:28Z DEBUG Updating managed permissions for vault 2019-01-17T11:03:28Z DEBUG Updating managed permission: System: Add Vaults 2019-01-17T11:03:28Z DEBUG Updating ACI for managed permission: System: Add Vaults 2019-01-17T11:03:28Z DEBUG Adding ACI u'(target = "ldap:///cn=vaults,cn=kra,dc=local")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=local";)' to dc=local 2019-01-17T11:03:28Z DEBUG Updating managed permission: System: Delete Vaults 2019-01-17T11:03:28Z DEBUG Updating ACI for managed permission: System: Delete Vaults 2019-01-17T11:03:29Z DEBUG Adding ACI u'(target = "ldap:///cn=vaults,cn=kra,dc=local")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=local";)' to dc=local 2019-01-17T11:03:29Z DEBUG Updating managed permission: System: Manage Vault Membership 2019-01-17T11:03:29Z DEBUG Updating ACI for managed permission: System: Manage Vault Membership 2019-01-17T11:03:29Z DEBUG Adding ACI u'(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=local")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=local";)' to dc=local 2019-01-17T11:03:29Z DEBUG Updating managed permission: System: Manage Vault Ownership 2019-01-17T11:03:29Z DEBUG Updating ACI for managed permission: System: Manage Vault Ownership 2019-01-17T11:03:29Z DEBUG Adding ACI u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=local")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=local";)' to dc=local 2019-01-17T11:03:29Z DEBUG Updating managed permission: System: Modify Vaults 2019-01-17T11:03:29Z DEBUG Updating ACI for managed permission: System: Modify Vaults 2019-01-17T11:03:29Z DEBUG Adding ACI u'(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=local")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=local";)' to dc=local 2019-01-17T11:03:29Z DEBUG Updating managed permission: System: Read Vaults 2019-01-17T11:03:29Z DEBUG Updating ACI for managed permission: System: Read Vaults 2019-01-17T11:03:29Z DEBUG Adding ACI u'(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=local")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=local";)' to dc=local 2019-01-17T11:03:29Z DEBUG Updating managed permissions for vaultcontainer 2019-01-17T11:03:29Z DEBUG Updating managed permission: System: Add Vault Containers 2019-01-17T11:03:29Z DEBUG Updating ACI for managed permission: System: Add Vault Containers 2019-01-17T11:03:29Z DEBUG Adding ACI u'(target = "ldap:///cn=vaults,cn=kra,dc=local")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=local";)' to dc=local 2019-01-17T11:03:29Z DEBUG Updating managed permission: System: Delete Vault Containers 2019-01-17T11:03:29Z DEBUG Updating ACI for managed permission: System: Delete Vault Containers 2019-01-17T11:03:29Z DEBUG Adding ACI u'(target = "ldap:///cn=vaults,cn=kra,dc=local")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=local";)' to dc=local 2019-01-17T11:03:29Z DEBUG Updating managed permission: System: Manage Vault Container Ownership 2019-01-17T11:03:29Z DEBUG Updating ACI for managed permission: System: Manage Vault Container Ownership 2019-01-17T11:03:29Z DEBUG Adding ACI u'(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=local")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=local";)' to dc=local 2019-01-17T11:03:29Z DEBUG Updating managed permission: System: Modify Vault Containers 2019-01-17T11:03:29Z DEBUG Updating ACI for managed permission: System: Modify Vault Containers 2019-01-17T11:03:29Z DEBUG Adding ACI u'(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=local")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=local";)' to dc=local 2019-01-17T11:03:29Z DEBUG Updating managed permission: System: Read Vault Containers 2019-01-17T11:03:29Z DEBUG Updating ACI for managed permission: System: Read Vault Containers 2019-01-17T11:03:29Z DEBUG Adding ACI u'(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=local")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=local";)' to dc=local 2019-01-17T11:03:29Z DEBUG Updating non-object managed permissions 2019-01-17T11:03:29Z DEBUG Updating managed permission: System: Add CA Certificate For Renewal 2019-01-17T11:03:29Z DEBUG Updating ACI for managed permission: System: Add CA Certificate For Renewal 2019-01-17T11:03:29Z DEBUG Adding ACI u'(target = "ldap:///cn=caSigningCert cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(targetfilter = "(objectclass=pkiuser)")(version 3.0;acl "permission:System: Add CA Certificate For Renewal";allow (add) groupdn = "ldap:///cn=System: Add CA Certificate For Renewal,cn=permissions,cn=pbac,dc=local";)' to cn=ca_renewal,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:29Z DEBUG Updating managed permission: System: Add Certificate Store Entry 2019-01-17T11:03:29Z DEBUG Updating ACI for managed permission: System: Add Certificate Store Entry 2019-01-17T11:03:29Z DEBUG Adding ACI u'(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Add Certificate Store Entry";allow (add) groupdn = "ldap:///cn=System: Add Certificate Store Entry,cn=permissions,cn=pbac,dc=local";)' to cn=certificates,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:29Z DEBUG Updating managed permission: System: Compat Tree ID View targets 2019-01-17T11:03:29Z DEBUG Updating ACI for managed permission: System: Compat Tree ID View targets 2019-01-17T11:03:29Z DEBUG Adding ACI u'(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=local")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)' to dc=local 2019-01-17T11:03:29Z DEBUG Updating managed permission: System: Modify CA Certificate 2019-01-17T11:03:29Z DEBUG Updating ACI for managed permission: System: Modify CA Certificate 2019-01-17T11:03:29Z DEBUG Adding ACI u'(targetattr = "cacertificate")(targetfilter = "(objectclass=pkica)")(version 3.0;acl "permission:System: Modify CA Certificate";allow (write) groupdn = "ldap:///cn=System: Modify CA Certificate,cn=permissions,cn=pbac,dc=local";)' to cn=CAcert,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:29Z DEBUG Updating managed permission: System: Modify CA Certificate For Renewal 2019-01-17T11:03:29Z DEBUG Updating ACI for managed permission: System: Modify CA Certificate For Renewal 2019-01-17T11:03:29Z DEBUG Adding ACI u'(targetattr = "usercertificate")(target = "ldap:///cn=caSigningCert cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=local")(targetfilter = "(objectclass=pkiuser)")(version 3.0;acl "permission:System: Modify CA Certificate For Renewal";allow (write) groupdn = "ldap:///cn=System: Modify CA Certificate For Renewal,cn=permissions,cn=pbac,dc=local";)' to cn=ca_renewal,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:29Z DEBUG Updating managed permission: System: Modify Certificate Store Entry 2019-01-17T11:03:29Z DEBUG Updating ACI for managed permission: System: Modify Certificate Store Entry 2019-01-17T11:03:29Z DEBUG Adding ACI u'(targetattr = "cacertificate || ipacertissuerserial || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Modify Certificate Store Entry";allow (write) groupdn = "ldap:///cn=System: Modify Certificate Store Entry,cn=permissions,cn=pbac,dc=local";)' to cn=certificates,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:29Z DEBUG Updating managed permission: System: Read AD Domains 2019-01-17T11:03:29Z DEBUG Updating ACI for managed permission: System: Read AD Domains 2019-01-17T11:03:29Z DEBUG Adding ACI u'(targetattr = "cn || createtimestamp || entryusn || ipantdomainguid || ipantfallbackprimarygroup || ipantflatname || ipantsecurityidentifier || modifytimestamp || objectclass")(target = "ldap:///cn=ad,cn=etc,dc=local")(targetfilter = "(objectclass=ipantdomainattrs)")(version 3.0;acl "permission:System: Read AD Domains";allow (compare,read,search) userdn = "ldap:///all";)' to cn=etc,dc=local 2019-01-17T11:03:29Z DEBUG Updating managed permission: System: Read CA Certificate 2019-01-17T11:03:29Z DEBUG Updating ACI for managed permission: System: Read CA Certificate 2019-01-17T11:03:29Z DEBUG Adding ACI u'(targetattr = "authorityrevocationlist || cacertificate || certificaterevocationlist || cn || createtimestamp || crosscertificatepair || entryusn || modifytimestamp || objectclass")(targetfilter = "(objectclass=pkica)")(version 3.0;acl "permission:System: Read CA Certificate";allow (compare,read,search) userdn = "ldap:///anyone";)' to cn=CAcert,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:29Z DEBUG Updating managed permission: System: Read CA Renewal Information 2019-01-17T11:03:29Z DEBUG Updating ACI for managed permission: System: Read CA Renewal Information 2019-01-17T11:03:29Z DEBUG Adding ACI u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || usercertificate")(targetfilter = "(objectclass=pkiuser)")(version 3.0;acl "permission:System: Read CA Renewal Information";allow (compare,read,search) userdn = "ldap:///all";)' to cn=ca_renewal,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:29Z DEBUG Updating managed permission: System: Read Certificate Store Entries 2019-01-17T11:03:29Z DEBUG Updating ACI for managed permission: System: Read Certificate Store Entries 2019-01-17T11:03:29Z DEBUG Adding ACI u'(targetattr = "cacertificate || cn || createtimestamp || entryusn || ipacertissuerserial || ipacertsubject || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage || ipapublickey || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Read Certificate Store Entries";allow (compare,read,search) userdn = "ldap:///anyone";)' to cn=certificates,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:29Z DEBUG Updating managed permission: System: Read DNA Configuration 2019-01-17T11:03:29Z DEBUG Updating ACI for managed permission: System: Read DNA Configuration 2019-01-17T11:03:29Z DEBUG Adding ACI u'(targetattr = "cn || createtimestamp || dnahostname || dnaportnum || dnaremainingvalues || dnaremotebindmethod || dnaremoteconnprotocol || dnasecureportnum || entryusn || modifytimestamp || objectclass")(targetfilter = "(objectclass=dnasharedconfig)")(version 3.0;acl "permission:System: Read DNA Configuration";allow (compare,read,search) userdn = "ldap:///all";)' to cn=dna,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:29Z DEBUG Updating managed permission: System: Read DUA Profile 2019-01-17T11:03:29Z DEBUG Updating ACI for managed permission: System: Read DUA Profile 2019-01-17T11:03:29Z DEBUG Adding ACI u'(targetattr = "attributemap || authenticationmethod || bindtimelimit || cn || createtimestamp || credentiallevel || defaultsearchbase || defaultsearchscope || defaultserverlist || dereferencealiases || entryusn || followreferrals || modifytimestamp || objectclass || objectclassmap || ou || preferredserverlist || profilettl || searchtimelimit || serviceauthenticationmethod || servicecredentiallevel || servicesearchdescriptor")(targetfilter = "(|(objectclass=organizationalUnit)(objectclass=DUAConfigProfile))")(version 3.0;acl "permission:System: Read DUA Profile";allow (compare,read,search) userdn = "ldap:///anyone";)' to ou=profile,dc=local 2019-01-17T11:03:29Z DEBUG Updating managed permission: System: Read Domain Level 2019-01-17T11:03:29Z DEBUG Updating ACI for managed permission: System: Read Domain Level 2019-01-17T11:03:29Z DEBUG Adding ACI u'(targetattr = "createtimestamp || entryusn || ipadomainlevel || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipadomainlevelconfig)")(version 3.0;acl "permission:System: Read Domain Level";allow (compare,read,search) userdn = "ldap:///all";)' to cn=Domain Level,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:29Z DEBUG Updating managed permission: System: Read IPA Masters 2019-01-17T11:03:29Z DEBUG Updating ACI for managed permission: System: Read IPA Masters 2019-01-17T11:03:29Z DEBUG Adding ACI u'(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=local";)' to cn=masters,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:29Z DEBUG Updating managed permission: System: Read Replication Information 2019-01-17T11:03:29Z DEBUG Updating ACI for managed permission: System: Read Replication Information 2019-01-17T11:03:29Z DEBUG Adding ACI u'(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicachangecount || nsds5replicacleanruv || nsds5replicaid || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicatombstonepurgeinterval || nsds5replicatype || nsds5task || nsstate || objectclass")(targetfilter = "(objectclass=nsds5replica)")(version 3.0;acl "permission:System: Read Replication Information";allow (compare,read,search) userdn = "ldap:///all";)' to cn=replication,cn=etc,dc=local 2019-01-17T11:03:29Z DEBUG Updating managed permission: System: Remove Certificate Store Entry 2019-01-17T11:03:29Z DEBUG Updating ACI for managed permission: System: Remove Certificate Store Entry 2019-01-17T11:03:29Z DEBUG Adding ACI u'(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Remove Certificate Store Entry";allow (delete) groupdn = "ldap:///cn=System: Remove Certificate Store Entry,cn=permissions,cn=pbac,dc=local";)' to cn=certificates,cn=ipa,cn=etc,dc=local 2019-01-17T11:03:29Z DEBUG Deleting obsolete permission System: Read Creator and Modifier Operational Attributes 2019-01-17T11:03:29Z DEBUG raw: permission_del((u'System: Read Creator and Modifier Operational Attributes',), force=True, version=u'2.101') 2019-01-17T11:03:29Z DEBUG permission_del((u'System: Read Creator and Modifier Operational Attributes',), continue=False, force=True, version=u'2.101') 2019-01-17T11:03:29Z DEBUG Obsolete permission not found 2019-01-17T11:03:29Z DEBUG Deleting obsolete permission System: Read Timestamp and USN Operational Attributes 2019-01-17T11:03:29Z DEBUG raw: permission_del((u'System: Read Timestamp and USN Operational Attributes',), force=True, version=u'2.101') 2019-01-17T11:03:29Z DEBUG permission_del((u'System: Read Timestamp and USN Operational Attributes',), continue=False, force=True, version=u'2.101') 2019-01-17T11:03:29Z DEBUG Obsolete permission not found 2019-01-17T11:03:29Z DEBUG Executing upgrade plugin: update_read_replication_agreements_permission 2019-01-17T11:03:29Z DEBUG raw: update_read_replication_agreements_permission 2019-01-17T11:03:29Z DEBUG Old permission not found 2019-01-17T11:03:29Z DEBUG Executing upgrade plugin: update_idrange_baserid 2019-01-17T11:03:29Z DEBUG raw: update_idrange_baserid 2019-01-17T11:03:29Z DEBUG update_idrange_baserid: search for ipa-ad-trust-posix ID ranges with ipaBaseRID != 0 2019-01-17T11:03:29Z DEBUG update_idrange_baserid: no AD domain range with posix attributes found 2019-01-17T11:03:29Z DEBUG Executing upgrade plugin: update_passync_privilege_update 2019-01-17T11:03:29Z DEBUG raw: update_passync_privilege_update 2019-01-17T11:03:29Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:29Z DEBUG Add PassSync user as a member of PassSync privilege 2019-01-17T11:03:29Z DEBUG PassSync user not found, no update needed 2019-01-17T11:03:29Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:29Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:29Z DEBUG Executing upgrade plugin: update_dnsserver_configuration_into_ldap 2019-01-17T11:03:29Z DEBUG raw: update_dnsserver_configuration_into_ldap 2019-01-17T11:03:29Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:29Z DEBUG DNS container not found, nothing to upgrade 2019-01-17T11:03:29Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:29Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:29Z DEBUG Executing upgrade plugin: update_ldap_server_list 2019-01-17T11:03:29Z DEBUG raw: update_ldap_server_list 2019-01-17T11:03:29Z DEBUG Executing upgrade plugin: update_dna_shared_config 2019-01-17T11:03:29Z DEBUG raw: update_dna_shared_config 2019-01-17T11:03:29Z DEBUG Destroyed connection context.ldap2_139822039370512 2019-01-17T11:03:29Z DEBUG duration: 21 seconds 2019-01-17T11:03:29Z DEBUG [8/9]: stopping directory server 2019-01-17T11:03:29Z DEBUG Destroyed connection context.ldap2_139822069897104 2019-01-17T11:03:29Z DEBUG Starting external process 2019-01-17T11:03:29Z DEBUG args=/bin/systemctl stop dirsrv@LOCAL.service 2019-01-17T11:03:31Z DEBUG Process finished, return code=0 2019-01-17T11:03:31Z DEBUG stdout= 2019-01-17T11:03:31Z DEBUG stderr= 2019-01-17T11:03:31Z DEBUG Stop of dirsrv@LOCAL.service complete 2019-01-17T11:03:31Z DEBUG duration: 1 seconds 2019-01-17T11:03:31Z DEBUG [9/9]: restoring configuration 2019-01-17T11:03:31Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:31Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:31Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:31Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:31Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:31Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:31Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:31Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:31Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:31Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:31Z DEBUG duration: 0 seconds 2019-01-17T11:03:31Z DEBUG Done. 2019-01-17T11:03:31Z INFO Update complete 2019-01-17T11:03:31Z INFO Upgrading the configuration of the IPA services 2019-01-17T11:03:31Z DEBUG IPA version 4.6.4-10.el7.centos 2019-01-17T11:03:31Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2019-01-17T11:03:31Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:31Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2019-01-17T11:03:31Z DEBUG Starting external process 2019-01-17T11:03:31Z DEBUG args=/bin/systemctl is-active dirsrv@LOCAL.service 2019-01-17T11:03:31Z DEBUG Process finished, return code=3 2019-01-17T11:03:31Z DEBUG stdout=unknown 2019-01-17T11:03:31Z DEBUG stderr= 2019-01-17T11:03:31Z DEBUG Starting external process 2019-01-17T11:03:31Z DEBUG args=/bin/systemctl start dirsrv@LOCAL.service 2019-01-17T11:03:36Z DEBUG Process finished, return code=0 2019-01-17T11:03:36Z DEBUG stdout= 2019-01-17T11:03:36Z DEBUG stderr= 2019-01-17T11:03:36Z DEBUG Starting external process 2019-01-17T11:03:36Z DEBUG args=/bin/systemctl is-active dirsrv@LOCAL.service 2019-01-17T11:03:36Z DEBUG Process finished, return code=0 2019-01-17T11:03:36Z DEBUG stdout=active 2019-01-17T11:03:36Z DEBUG stderr= 2019-01-17T11:03:36Z DEBUG wait_for_open_ports: localhost [389] timeout 300 2019-01-17T11:03:36Z DEBUG waiting for port: 389 2019-01-17T11:03:36Z DEBUG SUCCESS: port: 389 2019-01-17T11:03:36Z DEBUG Start of dirsrv@LOCAL.service complete 2019-01-17T11:03:36Z DEBUG Created connection context.ldap2_139822069897104 2019-01-17T11:03:36Z INFO [Verifying that root certificate is published] 2019-01-17T11:03:36Z DEBUG Certificate file exists 2019-01-17T11:03:36Z DEBUG Fix permission of /etc/httpd/alias to 755 2019-01-17T11:03:36Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:36Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2019-01-17T11:03:36Z DEBUG Trying to find certificate subject base in sysupgrade 2019-01-17T11:03:36Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:36Z DEBUG Found certificate subject base in sysupgrade: O=LOCAL 2019-01-17T11:03:36Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:36Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:36Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:36Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2019-01-17T11:03:36Z DEBUG request POST http://centos75.local:8080/ca/admin/ca/getStatus 2019-01-17T11:03:36Z DEBUG request body '' 2019-01-17T11:03:36Z DEBUG httplib request failed: Traceback (most recent call last): File "/usr/lib/python2.7/site-packages/ipapython/dogtag.py", line 220, in _httplib_request conn.request(method, uri, body=request_body, headers=headers) File "/usr/lib64/python2.7/httplib.py", line 1041, in request self._send_request(method, url, body, headers) File "/usr/lib64/python2.7/httplib.py", line 1075, in _send_request self.endheaders(body) File "/usr/lib64/python2.7/httplib.py", line 1037, in endheaders self._send_output(message_body) File "/usr/lib64/python2.7/httplib.py", line 881, in _send_output self.send(msg) File "/usr/lib64/python2.7/httplib.py", line 843, in send self.connect() File "/usr/lib64/python2.7/httplib.py", line 824, in connect self.timeout, self.source_address) File "/usr/lib64/python2.7/socket.py", line 571, in create_connection raise err error: [Errno 111] Connection refused 2019-01-17T11:03:36Z DEBUG Failed to check CA status: cannot connect to 'http://centos75.local:8080/ca/admin/ca/getStatus': [Errno 111] Connection refused 2019-01-17T11:03:36Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:36Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2019-01-17T11:03:36Z DEBUG Ensuring that service pki-tomcatd@pki-tomcat is not running while the next set of commands is being executed. 2019-01-17T11:03:36Z DEBUG Starting external process 2019-01-17T11:03:36Z DEBUG args=/bin/systemctl is-active pki-tomcatd@pki-tomcat.service 2019-01-17T11:03:36Z DEBUG Process finished, return code=3 2019-01-17T11:03:36Z DEBUG stdout=unknown 2019-01-17T11:03:36Z DEBUG stderr= 2019-01-17T11:03:36Z DEBUG Service pki-tomcatd@pki-tomcat is not running, continue. 2019-01-17T11:03:36Z DEBUG Starting external process 2019-01-17T11:03:36Z DEBUG args=/bin/systemctl is-active pki-tomcatd@pki-tomcat.service 2019-01-17T11:03:36Z DEBUG Process finished, return code=3 2019-01-17T11:03:36Z DEBUG stdout=unknown 2019-01-17T11:03:36Z DEBUG stderr= 2019-01-17T11:03:36Z INFO [Migrate CRL publish directory] 2019-01-17T11:03:36Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:36Z DEBUG Starting external process 2019-01-17T11:03:36Z DEBUG args=/usr/sbin/selinuxenabled 2019-01-17T11:03:36Z DEBUG Process finished, return code=0 2019-01-17T11:03:36Z DEBUG stdout= 2019-01-17T11:03:36Z DEBUG stderr= 2019-01-17T11:03:36Z DEBUG Starting external process 2019-01-17T11:03:36Z DEBUG args=/sbin/restorecon /var/lib/ipa/pki-ca/publish 2019-01-17T11:03:36Z DEBUG Process finished, return code=0 2019-01-17T11:03:36Z DEBUG stdout= 2019-01-17T11:03:36Z DEBUG stderr= 2019-01-17T11:03:36Z INFO Publish directory already set to new location 2019-01-17T11:03:36Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:36Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:36Z INFO [Verifying that CA proxy configuration is correct] 2019-01-17T11:03:36Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:36Z DEBUG Proxy configuration up-to-date 2019-01-17T11:03:36Z DEBUG Starting external process 2019-01-17T11:03:36Z DEBUG args=/bin/systemctl start pki-tomcatd@pki-tomcat.service 2019-01-17T11:03:37Z DEBUG Process finished, return code=0 2019-01-17T11:03:37Z DEBUG stdout= 2019-01-17T11:03:37Z DEBUG stderr= 2019-01-17T11:03:37Z DEBUG Starting external process 2019-01-17T11:03:37Z DEBUG args=/bin/systemctl is-active pki-tomcatd@pki-tomcat.service 2019-01-17T11:03:37Z DEBUG Process finished, return code=0 2019-01-17T11:03:37Z DEBUG stdout=active 2019-01-17T11:03:37Z DEBUG stderr= 2019-01-17T11:03:37Z DEBUG wait_for_open_ports: localhost [8080, 8443] timeout 300 2019-01-17T11:03:37Z DEBUG waiting for port: 8080 2019-01-17T11:03:37Z DEBUG Failed to connect to port 8080 tcp on ::1 2019-01-17T11:03:37Z DEBUG Failed to connect to port 8080 tcp on 127.0.0.1 2019-01-17T11:03:38Z DEBUG SUCCESS: port: 8080 2019-01-17T11:03:38Z DEBUG waiting for port: 8443 2019-01-17T11:03:38Z DEBUG Failed to connect to port 8443 tcp on ::1 2019-01-17T11:03:38Z DEBUG Failed to connect to port 8443 tcp on 127.0.0.1 2019-01-17T11:03:39Z DEBUG SUCCESS: port: 8443 2019-01-17T11:03:39Z DEBUG Start of pki-tomcatd@pki-tomcat.service complete 2019-01-17T11:03:39Z DEBUG Waiting until the CA is running 2019-01-17T11:03:39Z DEBUG request POST http://centos75.local:8080/ca/admin/ca/getStatus 2019-01-17T11:03:39Z DEBUG request body '' 2019-01-17T11:03:44Z DEBUG response status 200 2019-01-17T11:03:44Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/xml Content-Length: 167 Date: Thu, 17 Jan 2019 11:03:44 GMT 2019-01-17T11:03:44Z DEBUG response body '1CArunning10.5.9-6.el7' 2019-01-17T11:03:44Z DEBUG The CA status is: running 2019-01-17T11:03:44Z DEBUG Starting external process 2019-01-17T11:03:44Z DEBUG args=/bin/systemctl is-active certmonger.service 2019-01-17T11:03:44Z DEBUG Process finished, return code=0 2019-01-17T11:03:44Z DEBUG stdout=active 2019-01-17T11:03:44Z DEBUG stderr= 2019-01-17T11:03:44Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:44Z INFO [Verifying that KDC configuration is using ipa-kdb backend] 2019-01-17T11:03:44Z DEBUG dbmodules already updated in /etc/krb5.conf 2019-01-17T11:03:44Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:44Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2019-01-17T11:03:44Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:44Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:44Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2019-01-17T11:03:44Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:44Z DEBUG Starting external process 2019-01-17T11:03:44Z DEBUG args=/usr/sbin/selinuxenabled 2019-01-17T11:03:44Z DEBUG Process finished, return code=0 2019-01-17T11:03:44Z DEBUG stdout= 2019-01-17T11:03:44Z DEBUG stderr= 2019-01-17T11:03:44Z DEBUG Starting external process 2019-01-17T11:03:44Z DEBUG args=/usr/sbin/getsebool httpd_can_network_connect 2019-01-17T11:03:44Z DEBUG Process finished, return code=0 2019-01-17T11:03:44Z DEBUG stdout=httpd_can_network_connect --> on 2019-01-17T11:03:44Z DEBUG stderr= 2019-01-17T11:03:44Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:44Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:44Z DEBUG Starting external process 2019-01-17T11:03:44Z DEBUG args=/usr/sbin/getsebool httpd_dbus_sssd 2019-01-17T11:03:44Z DEBUG Process finished, return code=0 2019-01-17T11:03:44Z DEBUG stdout=httpd_dbus_sssd --> on 2019-01-17T11:03:44Z DEBUG stderr= 2019-01-17T11:03:44Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:44Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:44Z DEBUG Starting external process 2019-01-17T11:03:44Z DEBUG args=/usr/sbin/getsebool httpd_run_ipa 2019-01-17T11:03:44Z DEBUG Process finished, return code=0 2019-01-17T11:03:44Z DEBUG stdout=httpd_run_ipa --> on 2019-01-17T11:03:44Z DEBUG stderr= 2019-01-17T11:03:44Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:44Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:44Z DEBUG Starting external process 2019-01-17T11:03:44Z DEBUG args=/usr/sbin/getsebool httpd_manage_ipa 2019-01-17T11:03:44Z DEBUG Process finished, return code=0 2019-01-17T11:03:44Z DEBUG stdout=httpd_manage_ipa --> on 2019-01-17T11:03:44Z DEBUG stderr= 2019-01-17T11:03:44Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:44Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:44Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:44Z DEBUG Starting external process 2019-01-17T11:03:44Z DEBUG args=/bin/systemctl is-active certmonger.service 2019-01-17T11:03:44Z DEBUG Process finished, return code=0 2019-01-17T11:03:44Z DEBUG stdout=active 2019-01-17T11:03:44Z DEBUG stderr= 2019-01-17T11:03:44Z DEBUG Starting external process 2019-01-17T11:03:44Z DEBUG args=/bin/systemctl is-active oddjobd.service 2019-01-17T11:03:44Z DEBUG Process finished, return code=0 2019-01-17T11:03:44Z DEBUG stdout=active 2019-01-17T11:03:44Z DEBUG stderr= 2019-01-17T11:03:44Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:44Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:44Z DEBUG Starting external process 2019-01-17T11:03:44Z DEBUG args=/bin/systemctl is-enabled oddjobd.service 2019-01-17T11:03:44Z DEBUG Process finished, return code=0 2019-01-17T11:03:44Z DEBUG stdout=enabled 2019-01-17T11:03:44Z DEBUG stderr= 2019-01-17T11:03:44Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:44Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:44Z DEBUG Starting external process 2019-01-17T11:03:44Z DEBUG args=/bin/systemctl enable oddjobd.service 2019-01-17T11:03:44Z DEBUG Process finished, return code=0 2019-01-17T11:03:44Z DEBUG stdout= 2019-01-17T11:03:44Z DEBUG stderr= 2019-01-17T11:03:44Z DEBUG Starting external process 2019-01-17T11:03:44Z DEBUG args=/bin/systemctl start oddjobd.service 2019-01-17T11:03:44Z DEBUG Process finished, return code=0 2019-01-17T11:03:44Z DEBUG stdout= 2019-01-17T11:03:44Z DEBUG stderr= 2019-01-17T11:03:44Z DEBUG Starting external process 2019-01-17T11:03:44Z DEBUG args=/bin/systemctl is-active oddjobd.service 2019-01-17T11:03:44Z DEBUG Process finished, return code=0 2019-01-17T11:03:44Z DEBUG stdout=active 2019-01-17T11:03:44Z DEBUG stderr= 2019-01-17T11:03:44Z DEBUG Start of oddjobd.service complete 2019-01-17T11:03:44Z DEBUG Backing up system configuration file '/etc/sysconfig/dirsrv' 2019-01-17T11:03:44Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2019-01-17T11:03:44Z DEBUG Starting external process 2019-01-17T11:03:44Z DEBUG args=/usr/sbin/selinuxenabled 2019-01-17T11:03:44Z DEBUG Process finished, return code=0 2019-01-17T11:03:44Z DEBUG stdout= 2019-01-17T11:03:44Z DEBUG stderr= 2019-01-17T11:03:44Z DEBUG Starting external process 2019-01-17T11:03:44Z DEBUG args=/sbin/restorecon /etc/sysconfig/dirsrv 2019-01-17T11:03:44Z DEBUG Process finished, return code=0 2019-01-17T11:03:44Z DEBUG stdout= 2019-01-17T11:03:44Z DEBUG stderr= 2019-01-17T11:03:44Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:44Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2019-01-17T11:03:44Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:44Z DEBUG Starting external process 2019-01-17T11:03:44Z DEBUG args=/bin/systemctl is-active ntpd.service 2019-01-17T11:03:44Z DEBUG Process finished, return code=3 2019-01-17T11:03:44Z DEBUG stdout=inactive 2019-01-17T11:03:44Z DEBUG stderr= 2019-01-17T11:03:44Z DEBUG Destroyed connection context.ldap2_139822069897104 2019-01-17T11:03:44Z DEBUG Starting external process 2019-01-17T11:03:44Z DEBUG args=/bin/systemctl stop dirsrv@LOCAL.service 2019-01-17T11:03:46Z DEBUG Process finished, return code=0 2019-01-17T11:03:46Z DEBUG stdout= 2019-01-17T11:03:46Z DEBUG stderr= 2019-01-17T11:03:46Z DEBUG Stop of dirsrv@LOCAL.service complete 2019-01-17T11:03:46Z INFO [Fix DS schema file syntax] 2019-01-17T11:03:46Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:46Z DEBUG Remove extra dollar sign in ipaSudoRule 2019-01-17T11:03:46Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:46Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:46Z INFO [Removing RA cert from DS NSS database] 2019-01-17T11:03:46Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:46Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2019-01-17T11:03:46Z DEBUG Starting external process 2019-01-17T11:03:46Z DEBUG args=/usr/bin/certutil -d dbm:/etc/dirsrv/slapd-LOCAL/ -L -n CN=IPA RA,O=LOCAL -a -f /etc/dirsrv/slapd-LOCAL/pwdfile.txt 2019-01-17T11:03:46Z DEBUG Process finished, return code=255 2019-01-17T11:03:46Z DEBUG stdout= 2019-01-17T11:03:46Z DEBUG stderr=certutil: Could not find cert: CN=IPA RA,O=LOCAL : PR_FILE_NOT_FOUND_ERROR: File not found 2019-01-17T11:03:46Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:46Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:46Z DEBUG Starting external process 2019-01-17T11:03:46Z DEBUG args=/bin/systemctl start dirsrv@LOCAL.service 2019-01-17T11:03:50Z DEBUG Process finished, return code=0 2019-01-17T11:03:50Z DEBUG stdout= 2019-01-17T11:03:50Z DEBUG stderr= 2019-01-17T11:03:50Z DEBUG Starting external process 2019-01-17T11:03:50Z DEBUG args=/bin/systemctl is-active dirsrv@LOCAL.service 2019-01-17T11:03:50Z DEBUG Process finished, return code=0 2019-01-17T11:03:50Z DEBUG stdout=active 2019-01-17T11:03:50Z DEBUG stderr= 2019-01-17T11:03:50Z DEBUG wait_for_open_ports: localhost [389] timeout 300 2019-01-17T11:03:50Z DEBUG waiting for port: 389 2019-01-17T11:03:50Z DEBUG SUCCESS: port: 389 2019-01-17T11:03:50Z DEBUG Start of dirsrv@LOCAL.service complete 2019-01-17T11:03:50Z DEBUG Created connection context.ldap2_139822069897104 2019-01-17T11:03:50Z INFO [Enable sidgen and extdom plugins by default] 2019-01-17T11:03:50Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:50Z DEBUG flushing ldapi://%2fvar%2frun%2fslapd-LOCAL.socket from SchemaCache 2019-01-17T11:03:50Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-LOCAL.socket conn= 2019-01-17T11:03:50Z DEBUG sidgen plugin is already configured 2019-01-17T11:03:50Z DEBUG extdom plugin is already configured 2019-01-17T11:03:50Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:50Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:50Z DEBUG Starting external process 2019-01-17T11:03:50Z DEBUG args=/bin/systemctl stop httpd.service 2019-01-17T11:03:50Z DEBUG Process finished, return code=0 2019-01-17T11:03:50Z DEBUG stdout= 2019-01-17T11:03:50Z DEBUG stderr= 2019-01-17T11:03:50Z DEBUG Stop of httpd.service complete 2019-01-17T11:03:50Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2019-01-17T11:03:50Z DEBUG Starting external process 2019-01-17T11:03:50Z DEBUG args=/usr/bin/certutil -d dbm:/etc/httpd/alias -L -f /etc/httpd/alias/pwdfile.txt 2019-01-17T11:03:50Z DEBUG Process finished, return code=0 2019-01-17T11:03:50Z DEBUG stdout= Certificate Nickname Trust Attributes SSL,S/MIME,JAR/XPI Server-Cert u,u,u LOCAL IPA CA CT,C,C 2019-01-17T11:03:50Z DEBUG stderr= 2019-01-17T11:03:50Z DEBUG Starting external process 2019-01-17T11:03:50Z DEBUG args=/usr/bin/certutil -d dbm:/etc/httpd/alias -L -n LOCAL IPA CA -a -f /etc/httpd/alias/pwdfile.txt 2019-01-17T11:03:50Z DEBUG Process finished, return code=0 2019-01-17T11:03:50Z DEBUG stdout=-----BEGIN CERTIFICATE----- MIIDeTCCAmGgAwIBAgIBATANBgkqhkiG9w0BAQsFADAwMQ4wDAYDVQQKDAVMT0NB TDEeMBwGA1UEAwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB4XDTE5MDExNzEwMzY0 MFoXDTM5MDExNzEwMzY0MFowMDEOMAwGA1UECgwFTE9DQUwxHjAcBgNVBAMMFUNl cnRpZmljYXRlIEF1dGhvcml0eTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoC ggEBAKZb97CB23Y/pVfUJDKG0Ul69AV+VipQ/VG6X4Xj16a07871RLLHMSx7p4dH kLmLe0R876dzQEE+z6fR0DXaCMISDlS9Bq9uVrAKKCYQRfT7O6TloVYbseh2os2h xdublLnJEZjwVDhyB6fhjfdx8GtPBETiLM37M7ZY9+6No+WkjSrPHlxPEzV/a8cB FN/iHQ1+5/Hbvc1NG5V67DJy+WLNRRYhMi9v7OSF8BbSl8ApHJMM0qYNLhvKuY5V N8nRDB0vwkea2cywI2wG9c2/vufzzh8F0MBMIpkL/LtanaBtZ0C6oSLsqGVBS+0q d8sQ5zZFAzdipndQd6xuzwmc6C0CAwEAAaOBnTCBmjAfBgNVHSMEGDAWgBRUEnLK tz1ZHkZQdIH6aDD/IGomxDAPBgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB/wQEAwIB xjAdBgNVHQ4EFgQUVBJyyrc9WR5GUHSB+mgw/yBqJsQwNwYIKwYBBQUHAQEEKzAp MCcGCCsGAQUFBzABhhtodHRwOi8vaXBhLWNhLmxvY2FsL2NhL29jc3AwDQYJKoZI hvcNAQELBQADggEBAI+bg4Nwz7fO3xdpD4X73ASnWPIWJoF3NX1qrn0vWjImbqyI gixTCWf2YXEGYYOU1czGj+M14HPVC8cKZBpobPY7ESZNDVrl07/iqkumdooibeqW KMo0UsOX9iNcnLtJdCXl7+yKlzUm16C8Ud+b0WuXmWwUg+DPf/xveYLw9058AoyA ODURXE1hx8J/tQKV03pmJ5CQfetVCxUyqUvHf50IV9+Td2fQAyIIt2rQExRn1R0a TmZPFeUVkbIDYITl79GQKHXSfJkCAFgzUR2EA0kmBZcCwzGM3Iqh1YUUQE9BPreb 3fWVexLT8Q7y4qP/qTxidd8SG0OGwFRkBH0fhFs= -----END CERTIFICATE----- 2019-01-17T11:03:50Z DEBUG stderr= 2019-01-17T11:03:50Z DEBUG Starting external process 2019-01-17T11:03:50Z DEBUG args=/usr/bin/modutil -dbdir /etc/httpd/alias -force -list Root Certs 2019-01-17T11:03:51Z DEBUG Process finished, return code=0 2019-01-17T11:03:51Z DEBUG stdout= ----------------------------------------------------------- Name: Root Certs Library file: /etc/httpd/alias/libnssckbi.so Manufacturer: PKCS#11 Kit Description: PKCS#11 Kit Trust Module PKCS #11 Version 2.40 Library Version: 0.23 Cipher Enable Flags: None Default Mechanism Flags: None Slot: /etc/pki/ca-trust/source Slot Mechanism Flags: None Manufacturer: PKCS#11 Kit Type: Software Version Number: 0.23 Firmware Version: 0.0 Status: DISABLED (user disabled) Token Name: System Trust Token Manufacturer: PKCS#11 Kit Token Model: p11-kit-trust Token Serial Number: 1 Token Version: 0.23 Token Firmware Version: 0.0 Access: NOT Write Protected Login Type: Public (no login required) User Pin: NOT Initialized Slot: /usr/share/pki/ca-trust-source Slot Mechanism Flags: None Manufacturer: PKCS#11 Kit Type: Software Version Number: 0.23 Firmware Version: 0.0 Status: DISABLED (user disabled) Token Name: Default Trust Token Manufacturer: PKCS#11 Kit Token Model: p11-kit-trust Token Serial Number: 1 Token Version: 0.23 Token Firmware Version: 0.0 Access: NOT Write Protected Login Type: Public (no login required) User Pin: NOT Initialized ----------------------------------------------------------- 2019-01-17T11:03:51Z DEBUG stderr= 2019-01-17T11:03:51Z INFO [Updating HTTPD service IPA configuration] 2019-01-17T11:03:51Z DEBUG Starting external process 2019-01-17T11:03:51Z DEBUG args=/usr/sbin/selinuxenabled 2019-01-17T11:03:51Z DEBUG Process finished, return code=0 2019-01-17T11:03:51Z DEBUG stdout= 2019-01-17T11:03:51Z DEBUG stderr= 2019-01-17T11:03:51Z DEBUG Starting external process 2019-01-17T11:03:51Z DEBUG args=/sbin/restorecon /etc/systemd/system/httpd.service.d/ipa.conf 2019-01-17T11:03:51Z DEBUG Process finished, return code=0 2019-01-17T11:03:51Z DEBUG stdout= 2019-01-17T11:03:51Z DEBUG stderr= 2019-01-17T11:03:51Z DEBUG Starting external process 2019-01-17T11:03:51Z DEBUG args=/bin/systemctl --system daemon-reload 2019-01-17T11:03:51Z DEBUG Process finished, return code=0 2019-01-17T11:03:51Z DEBUG stdout= 2019-01-17T11:03:51Z DEBUG stderr= 2019-01-17T11:03:51Z INFO [Updating HTTPD service IPA WSGI configuration] 2019-01-17T11:03:51Z INFO Nothing to do for configure_httpd_wsgi_conf 2019-01-17T11:03:51Z INFO [Updating mod_nss protocol versions] 2019-01-17T11:03:51Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:51Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:51Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:51Z INFO [Updating mod_nss cipher suite] 2019-01-17T11:03:51Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:51Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:51Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:51Z INFO [Updating mod_nss enabling OCSP] 2019-01-17T11:03:51Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:51Z INFO [Fixing trust flags in /etc/httpd/alias] 2019-01-17T11:03:51Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:51Z DEBUG raw: ca_is_enabled(version=u'2.229') 2019-01-17T11:03:51Z DEBUG ca_is_enabled(version=u'2.229') 2019-01-17T11:03:51Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2019-01-17T11:03:51Z DEBUG Starting external process 2019-01-17T11:03:51Z DEBUG args=/usr/bin/certutil -d dbm:/etc/httpd/alias -L -n LOCAL IPA CA -a -f /etc/httpd/alias/pwdfile.txt 2019-01-17T11:03:51Z DEBUG Process finished, return code=0 2019-01-17T11:03:51Z DEBUG stdout=-----BEGIN CERTIFICATE----- MIIDeTCCAmGgAwIBAgIBATANBgkqhkiG9w0BAQsFADAwMQ4wDAYDVQQKDAVMT0NB TDEeMBwGA1UEAwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB4XDTE5MDExNzEwMzY0 MFoXDTM5MDExNzEwMzY0MFowMDEOMAwGA1UECgwFTE9DQUwxHjAcBgNVBAMMFUNl cnRpZmljYXRlIEF1dGhvcml0eTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoC ggEBAKZb97CB23Y/pVfUJDKG0Ul69AV+VipQ/VG6X4Xj16a07871RLLHMSx7p4dH kLmLe0R876dzQEE+z6fR0DXaCMISDlS9Bq9uVrAKKCYQRfT7O6TloVYbseh2os2h xdublLnJEZjwVDhyB6fhjfdx8GtPBETiLM37M7ZY9+6No+WkjSrPHlxPEzV/a8cB FN/iHQ1+5/Hbvc1NG5V67DJy+WLNRRYhMi9v7OSF8BbSl8ApHJMM0qYNLhvKuY5V N8nRDB0vwkea2cywI2wG9c2/vufzzh8F0MBMIpkL/LtanaBtZ0C6oSLsqGVBS+0q d8sQ5zZFAzdipndQd6xuzwmc6C0CAwEAAaOBnTCBmjAfBgNVHSMEGDAWgBRUEnLK tz1ZHkZQdIH6aDD/IGomxDAPBgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB/wQEAwIB xjAdBgNVHQ4EFgQUVBJyyrc9WR5GUHSB+mgw/yBqJsQwNwYIKwYBBQUHAQEEKzAp MCcGCCsGAQUFBzABhhtodHRwOi8vaXBhLWNhLmxvY2FsL2NhL29jc3AwDQYJKoZI hvcNAQELBQADggEBAI+bg4Nwz7fO3xdpD4X73ASnWPIWJoF3NX1qrn0vWjImbqyI gixTCWf2YXEGYYOU1czGj+M14HPVC8cKZBpobPY7ESZNDVrl07/iqkumdooibeqW KMo0UsOX9iNcnLtJdCXl7+yKlzUm16C8Ud+b0WuXmWwUg+DPf/xveYLw9058AoyA ODURXE1hx8J/tQKV03pmJ5CQfetVCxUyqUvHf50IV9+Td2fQAyIIt2rQExRn1R0a TmZPFeUVkbIDYITl79GQKHXSfJkCAFgzUR2EA0kmBZcCwzGM3Iqh1YUUQE9BPreb 3fWVexLT8Q7y4qP/qTxidd8SG0OGwFRkBH0fhFs= -----END CERTIFICATE----- 2019-01-17T11:03:51Z DEBUG stderr= 2019-01-17T11:03:51Z DEBUG Starting external process 2019-01-17T11:03:51Z DEBUG args=/usr/bin/certutil -d dbm:/etc/httpd/alias -M -n LOCAL IPA CA -t CT,C,C -f /etc/httpd/alias/pwdfile.txt 2019-01-17T11:03:51Z DEBUG Process finished, return code=0 2019-01-17T11:03:51Z DEBUG stdout= 2019-01-17T11:03:51Z DEBUG stderr= 2019-01-17T11:03:51Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:51Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:51Z INFO [Moving HTTPD service keytab to gssproxy] 2019-01-17T11:03:51Z DEBUG Starting external process 2019-01-17T11:03:51Z DEBUG args=/usr/sbin/selinuxenabled 2019-01-17T11:03:51Z DEBUG Process finished, return code=0 2019-01-17T11:03:51Z DEBUG stdout= 2019-01-17T11:03:51Z DEBUG stderr= 2019-01-17T11:03:51Z DEBUG Starting external process 2019-01-17T11:03:51Z DEBUG args=/sbin/restorecon /etc/gssproxy/10-ipa.conf 2019-01-17T11:03:51Z DEBUG Process finished, return code=0 2019-01-17T11:03:51Z DEBUG stdout= 2019-01-17T11:03:51Z DEBUG stderr= 2019-01-17T11:03:51Z DEBUG Starting external process 2019-01-17T11:03:51Z DEBUG args=/bin/systemctl restart gssproxy.service 2019-01-17T11:03:51Z DEBUG Process finished, return code=0 2019-01-17T11:03:51Z DEBUG stdout= 2019-01-17T11:03:51Z DEBUG stderr= 2019-01-17T11:03:51Z DEBUG Starting external process 2019-01-17T11:03:51Z DEBUG args=/bin/systemctl is-active gssproxy.service 2019-01-17T11:03:51Z DEBUG Process finished, return code=0 2019-01-17T11:03:51Z DEBUG stdout=active 2019-01-17T11:03:51Z DEBUG stderr= 2019-01-17T11:03:51Z DEBUG Restart of gssproxy.service complete 2019-01-17T11:03:51Z DEBUG Starting external process 2019-01-17T11:03:51Z DEBUG args=/bin/systemctl start httpd.service 2019-01-17T11:03:52Z DEBUG Process finished, return code=0 2019-01-17T11:03:52Z DEBUG stdout= 2019-01-17T11:03:52Z DEBUG stderr= 2019-01-17T11:03:52Z DEBUG Starting external process 2019-01-17T11:03:52Z DEBUG args=/bin/systemctl is-active httpd.service 2019-01-17T11:03:53Z DEBUG Process finished, return code=0 2019-01-17T11:03:53Z DEBUG stdout=active 2019-01-17T11:03:53Z DEBUG stderr= 2019-01-17T11:03:53Z DEBUG Start of httpd.service complete 2019-01-17T11:03:53Z INFO [Removing self-signed CA] 2019-01-17T11:03:53Z DEBUG Self-signed CA is not installed 2019-01-17T11:03:53Z INFO [Removing Dogtag 9 CA] 2019-01-17T11:03:53Z DEBUG Dogtag is version 10 or above 2019-01-17T11:03:53Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:53Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2019-01-17T11:03:53Z INFO [Checking for deprecated KDC configuration files] 2019-01-17T11:03:53Z INFO [Checking for deprecated backups of Samba configuration files] 2019-01-17T11:03:53Z DEBUG raw: ca_is_enabled(version=u'2.229') 2019-01-17T11:03:53Z DEBUG ca_is_enabled(version=u'2.229') 2019-01-17T11:03:53Z DEBUG raw: kra_is_enabled(version=u'2.229') 2019-01-17T11:03:53Z DEBUG kra_is_enabled(version=u'2.229') 2019-01-17T11:03:53Z DEBUG Cleaning up after pkispawn for the CA subsystem 2019-01-17T11:03:53Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:53Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2019-01-17T11:03:53Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:53Z INFO [Add missing CA DNS records] 2019-01-17T11:03:53Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:53Z DEBUG raw: dns_is_enabled(version=u'2.229') 2019-01-17T11:03:53Z DEBUG dns_is_enabled(version=u'2.229') 2019-01-17T11:03:53Z INFO DNS is not configured 2019-01-17T11:03:53Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:53Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:53Z INFO [Removing deprecated DNS configuration options] 2019-01-17T11:03:53Z INFO DNS is not configured 2019-01-17T11:03:53Z INFO [Ensuring minimal number of connections] 2019-01-17T11:03:53Z INFO DNS is not configured 2019-01-17T11:03:53Z INFO [Updating GSSAPI configuration in DNS] 2019-01-17T11:03:53Z INFO DNS is not configured 2019-01-17T11:03:53Z INFO [Updating pid-file configuration in DNS] 2019-01-17T11:03:53Z INFO DNS is not configured 2019-01-17T11:03:53Z INFO DNS is not configured 2019-01-17T11:03:53Z INFO DNS is not configured 2019-01-17T11:03:53Z INFO DNS is not configured 2019-01-17T11:03:53Z INFO DNS is not configured 2019-01-17T11:03:53Z INFO DNS is not configured 2019-01-17T11:03:53Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:53Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2019-01-17T11:03:53Z INFO DNS is not configured 2019-01-17T11:03:53Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:53Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:53Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:53Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:53Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:53Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:53Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:53Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2019-01-17T11:03:53Z INFO DNS is not configured 2019-01-17T11:03:53Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2019-01-17T11:03:53Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2019-01-17T11:03:53Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:54Z INFO [Upgrading CA schema] 2019-01-17T11:03:54Z DEBUG Processing schema LDIF file /usr/share/pki/server/conf/schema-certProfile.ldif 2019-01-17T11:03:54Z DEBUG Processing schema LDIF file /usr/share/pki/server/conf/schema-authority.ldif 2019-01-17T11:03:54Z DEBUG Not updating schema 2019-01-17T11:03:54Z INFO CA schema update complete (no changes) 2019-01-17T11:03:54Z INFO [Verifying that CA audit signing cert has 2 year validity] 2019-01-17T11:03:54Z DEBUG caSignedLogCert.cfg profile validity range is 720 2019-01-17T11:03:54Z INFO [Update certmonger certificate renewal configuration] 2019-01-17T11:03:55Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2019-01-17T11:03:55Z DEBUG Starting external process 2019-01-17T11:03:55Z DEBUG args=/usr/bin/certutil -d dbm:/etc/httpd/alias -L -n Server-Cert -a -f /etc/httpd/alias/pwdfile.txt 2019-01-17T11:03:55Z DEBUG Process finished, return code=0 2019-01-17T11:03:55Z DEBUG stdout=-----BEGIN CERTIFICATE----- MIIEdDCCA1ygAwIBAgIBCTANBgkqhkiG9w0BAQsFADAwMQ4wDAYDVQQKDAVMT0NB TDEeMBwGA1UEAwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB4XDTE5MDExNzEwMzkw OFoXDTIxMDExNzEwMzkwOFowKTEOMAwGA1UECgwFTE9DQUwxFzAVBgNVBAMMDmNl bnRvczc1LmxvY2FsMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzAus oh8/6kInI5fsGjGQGEYvRA5mCClJWtdFnhxI3/V2FoKGyd219aUECCs+xnt7qlV/ 1C8+HAq9Q6GQPAVf5sR7ECEEwb7pXdCFZUgXlefP5niCxSaHfpF4L6PgL2RaBeKK X192lc2Pgs/2+V9HBJjhU1fjqwaFQZOYB3P2f0LPP6x0UDrw3dPtc97RUvXzGrnY UYMSAP8y/1ybbi29LS1XZgN0WdbA3oen9svokyptkWnRVzg6IW1qfjfx32mBKYHs P24JNYfU62xC+7S8I7g8w+jH5lP12mDKAWmiqgUQ4MxFqlGAkYYloB+C2c7mVQWD uUPImUgAL937EAHoPwIDAQABo4IBnjCCAZowHwYDVR0jBBgwFoAUVBJyyrc9WR5G UHSB+mgw/yBqJsQwNwYIKwYBBQUHAQEEKzApMCcGCCsGAQUFBzABhhtodHRwOi8v aXBhLWNhLmxvY2FsL2NhL29jc3AwDgYDVR0PAQH/BAQDAgTwMB0GA1UdJQQWMBQG CCsGAQUFBwMBBggrBgEFBQcDAjBwBgNVHR8EaTBnMGWgLaArhilodHRwOi8vaXBh LWNhLmxvY2FsL2lwYS9jcmwvTWFzdGVyQ1JMLmJpbqI0pDIwMDEOMAwGA1UECgwF aXBhY2ExHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTAdBgNVHQ4EFgQU eZZXvdX1xKYb7TPSP8PGntpgK44wfgYDVR0RBHcwdYIOY2VudG9zNzUubG9jYWyg KQYKKwYBBAGCNxQCA6AbDBlIVFRQL2NlbnRvczc1LmxvY2FsQExPQ0FMoDgGBisG AQUCAqAuMCygBxsFTE9DQUyhITAfoAMCAQGhGDAWGwRIVFRQGw5jZW50b3M3NS5s b2NhbDANBgkqhkiG9w0BAQsFAAOCAQEAkG6rxtmYAg8b+BqJRQmvR1Mx54a2Stmg mkholLfiNTdoUubDzs8YP2gdCLe4ayySQysj6lFuHjbJhhQheM6ciTYkZSGP7Wbl rCy6VP+v4czNRlvFoIZGVRBR7CKTPjqlvuUMuUWyDiU2kjhe7p4Ltz4qKsaFhu+E aeBtxdbGHzdMaFwd9yAP0DVDjtCWlxIc3Qc59tuO6EkLbapHYHHwoE5GBx7eWprX xWnXzEuWV7e5wN1zQsAW3XAZX7UdaohCOhwLVU3mbzaFbQX6ObZoXWky0SmZQmr1 uGtHci1E9l4eM5G2wxwPpFg4ka0/pUe2o7i8YwGfw3O9wOliYuGOOA== -----END CERTIFICATE----- 2019-01-17T11:03:55Z DEBUG stderr= 2019-01-17T11:03:56Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2019-01-17T11:03:56Z DEBUG Starting external process 2019-01-17T11:03:56Z DEBUG args=/usr/bin/certutil -d dbm:/etc/dirsrv/slapd-LOCAL/ -L -n Server-Cert -a -f /etc/dirsrv/slapd-LOCAL/pwdfile.txt 2019-01-17T11:03:56Z DEBUG Process finished, return code=0 2019-01-17T11:03:56Z DEBUG stdout=-----BEGIN CERTIFICATE----- MIIEdDCCA1ygAwIBAgIBCDANBgkqhkiG9w0BAQsFADAwMQ4wDAYDVQQKDAVMT0NB TDEeMBwGA1UEAwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB4XDTE5MDExNzEwMzgx N1oXDTIxMDExNzEwMzgxN1owKTEOMAwGA1UECgwFTE9DQUwxFzAVBgNVBAMMDmNl bnRvczc1LmxvY2FsMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAs9SJ QnvRDaR1pGCCuIvHX4LpKKFGMAmyFQKKyJZ2VgFmP8JLSVwgB8TUd7ALrAVIxhnc cnFA9VITPF2qcEyxLMtRELg+OLLpPiNUhWjdrT1YYp8RFyMAI4HuA4d8j8j+IoZr R3VJuRpLgpeNLEjVzevqZFVoGhgrhgXglpjM+3BPt22UFnFio0rdpkH35F/R/HCM Xh/3o+oe6avZvhg5sLhWpg4IThVThzw4aD0AXlRNh7SlKBk1fYRhpE/smvbDFHhL ltxOe7yJ4S/Io+WuVWDolcqxxYLAzS2RTFpbt8MH+6HCMTAf+zJbxwtTqeCNIQsQ cpc4uFVWTae+KhTwTwIDAQABo4IBnjCCAZowHwYDVR0jBBgwFoAUVBJyyrc9WR5G UHSB+mgw/yBqJsQwNwYIKwYBBQUHAQEEKzApMCcGCCsGAQUFBzABhhtodHRwOi8v aXBhLWNhLmxvY2FsL2NhL29jc3AwDgYDVR0PAQH/BAQDAgTwMB0GA1UdJQQWMBQG CCsGAQUFBwMBBggrBgEFBQcDAjBwBgNVHR8EaTBnMGWgLaArhilodHRwOi8vaXBh LWNhLmxvY2FsL2lwYS9jcmwvTWFzdGVyQ1JMLmJpbqI0pDIwMDEOMAwGA1UECgwF aXBhY2ExHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTAdBgNVHQ4EFgQU ne6+3Foc3RTTvoVkAQ+zhMKtPk0wfgYDVR0RBHcwdYIOY2VudG9zNzUubG9jYWyg KQYKKwYBBAGCNxQCA6AbDBlsZGFwL2NlbnRvczc1LmxvY2FsQExPQ0FMoDgGBisG AQUCAqAuMCygBxsFTE9DQUyhITAfoAMCAQGhGDAWGwRsZGFwGw5jZW50b3M3NS5s b2NhbDANBgkqhkiG9w0BAQsFAAOCAQEAFjjGYb4VQD7KBlG0mK55my1RJ802jJis cX5oA0jLfuuftPL6FRoVc9pNUMMfwcAp3rP4gEi3GQbsBxQFE81uYs9ugXTnzWP0 tTUY5lfkej3IxjazdrYWpYsRJbL40yYxXMlcrWf1OttyKSoyTrhBNRHFd8lfsj/N t5J3ORqTpPhW6YAxt3dPXZmwNmjKla3LFt3oaFGuTCaJ3m9BKNgGaI7t5Gta2psC /JZuEQHb64H+rFzeXfCiuz+qdGTWNhZB0udApJytl+/2XRdQu1Yp9KvRxuKhnr+c 3ChZMT9x9XlexL8J6YglMRxB7Hrh4LI2HzaAJbSc4PoPObE4cLe+6g== -----END CERTIFICATE----- 2019-01-17T11:03:56Z DEBUG stderr= 2019-01-17T11:03:56Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2019-01-17T11:03:56Z DEBUG Starting external process 2019-01-17T11:03:56Z DEBUG args=/usr/bin/certutil -d dbm:/etc/pki/pki-tomcat/alias -L -f /etc/pki/pki-tomcat/alias/pwdfile.txt 2019-01-17T11:03:56Z DEBUG Process finished, return code=0 2019-01-17T11:03:56Z DEBUG stdout= Certificate Nickname Trust Attributes SSL,S/MIME,JAR/XPI caSigningCert cert-pki-ca CTu,Cu,Cu auditSigningCert cert-pki-ca u,u,Pu Server-Cert cert-pki-ca u,u,u ocspSigningCert cert-pki-ca u,u,u subsystemCert cert-pki-ca u,u,u 2019-01-17T11:03:56Z DEBUG stderr= 2019-01-17T11:03:57Z INFO Certmonger certificate renewal configuration already up-to-date 2019-01-17T11:03:57Z INFO [Enable PKIX certificate path discovery and validation] 2019-01-17T11:03:57Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:57Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:57Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:03:57Z INFO [Authorizing RA Agent to modify profiles] 2019-01-17T11:03:57Z INFO [Authorizing RA Agent to manage lightweight CAs] 2019-01-17T11:03:57Z INFO [Ensuring Lightweight CAs container exists in Dogtag database] 2019-01-17T11:03:57Z DEBUG Created connection context.ldap2_139822029540112 2019-01-17T11:03:57Z DEBUG flushing ldapi://%2fvar%2frun%2fslapd-LOCAL.socket from SchemaCache 2019-01-17T11:03:57Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-LOCAL.socket conn= 2019-01-17T11:04:00Z DEBUG Destroyed connection context.ldap2_139822029540112 2019-01-17T11:04:00Z INFO [Adding default OCSP URI configuration] 2019-01-17T11:04:00Z INFO pki-tomcat configuration changed, restart pki-tomcat 2019-01-17T11:04:00Z DEBUG Starting external process 2019-01-17T11:04:00Z DEBUG args=/bin/systemctl restart pki-tomcatd@pki-tomcat.service 2019-01-17T11:04:04Z DEBUG Process finished, return code=0 2019-01-17T11:04:04Z DEBUG stdout= 2019-01-17T11:04:04Z DEBUG stderr= 2019-01-17T11:04:04Z DEBUG Starting external process 2019-01-17T11:04:04Z DEBUG args=/bin/systemctl is-active pki-tomcatd@pki-tomcat.service 2019-01-17T11:04:04Z DEBUG Process finished, return code=0 2019-01-17T11:04:04Z DEBUG stdout=active 2019-01-17T11:04:04Z DEBUG stderr= 2019-01-17T11:04:04Z DEBUG wait_for_open_ports: localhost [8080, 8443] timeout 300 2019-01-17T11:04:04Z DEBUG waiting for port: 8080 2019-01-17T11:04:04Z DEBUG Failed to connect to port 8080 tcp on ::1 2019-01-17T11:04:04Z DEBUG Failed to connect to port 8080 tcp on 127.0.0.1 2019-01-17T11:04:06Z DEBUG SUCCESS: port: 8080 2019-01-17T11:04:06Z DEBUG waiting for port: 8443 2019-01-17T11:04:06Z DEBUG SUCCESS: port: 8443 2019-01-17T11:04:06Z DEBUG Restart of pki-tomcatd@pki-tomcat.service complete 2019-01-17T11:04:06Z DEBUG Waiting until the CA is running 2019-01-17T11:04:06Z DEBUG request POST http://centos75.local:8080/ca/admin/ca/getStatus 2019-01-17T11:04:06Z DEBUG request body '' 2019-01-17T11:04:14Z DEBUG response status 200 2019-01-17T11:04:14Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/xml Content-Length: 167 Date: Thu, 17 Jan 2019 11:04:14 GMT 2019-01-17T11:04:14Z DEBUG response body '1CArunning10.5.9-6.el7' 2019-01-17T11:04:14Z DEBUG The CA status is: running 2019-01-17T11:04:14Z INFO [Ensuring CA is using LDAPProfileSubsystem] 2019-01-17T11:04:14Z INFO [Migrating certificate profiles to LDAP] 2019-01-17T11:04:14Z DEBUG Created connection context.ldap2_139822014996240 2019-01-17T11:04:14Z DEBUG flushing ldapi://%2fvar%2frun%2fslapd-LOCAL.socket from SchemaCache 2019-01-17T11:04:14Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-LOCAL.socket conn= 2019-01-17T11:04:14Z DEBUG Destroyed connection context.ldap2_139822014996240 2019-01-17T11:04:14Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:14Z DEBUG request body '' 2019-01-17T11:04:16Z DEBUG response status 200 2019-01-17T11:04:16Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=FA6166767D9EA286D806A72B2278BCE3; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:16 GMT 2019-01-17T11:04:16Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:16Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:16Z DEBUG request body 'desc=This certificate profile is for enrolling server certificates using CMC.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=CMCAuth\nauthz.acl=group="Certificate Manager Agents"\nname=Server Certificate Enrollment using CMC\ninput.list=i1\ninput.i1.class_id=cmcCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,9\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=.*CN=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=720\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=720\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.9.default.class_id=commonNameToSANDefaultImpl\npolicyset.serverCertSet.9.default.name=copy CN to SAN Default\nprofileId=caCMCserverCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:16Z DEBUG response status 409 2019-01-17T11:04:16Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:16 GMT 2019-01-17T11:04:16Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:16Z DEBUG Error migrating 'caCMCserverCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:16Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caCMCserverCert?action=enable 2019-01-17T11:04:16Z DEBUG request body '' 2019-01-17T11:04:17Z DEBUG response status 500 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6520 Date: Thu, 17 Jan 2019 11:04:16 GMT Connection: close 2019-01-17T11:04:17Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)\n\tsun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)\n\tsun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)\n\tsun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)\n\tsun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:17Z DEBUG Failed to enable profile 'caCMCserverCert' (it is probably already enabled) 2019-01-17T11:04:17Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:17Z DEBUG request body '' 2019-01-17T11:04:17Z DEBUG response status 204 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=D0BD5049C4958CC7FB730BF564EA12E9; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:16 GMT 2019-01-17T11:04:17Z DEBUG response body '' 2019-01-17T11:04:17Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:17Z DEBUG request body '' 2019-01-17T11:04:17Z DEBUG response status 200 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=CB8E64545E5F8BED4B4D02A44CDE4B37; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:16 GMT 2019-01-17T11:04:17Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:17Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:17Z DEBUG request body 'desc=This certificate profile is for enrolling server certificates with ECC keys using CMC.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=CMCAuth\nauthz.acl=group="Certificate Manager Agents"\nname=Server Certificate wth ECC keys Enrollment using CMC\ninput.list=i1\ninput.i1.class_id=cmcCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,9\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=.*CN=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=720\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=720\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=EC\npolicyset.serverCertSet.3.constraint.params.keyParameters=nistp256,nistp384,nistp521\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.9.default.class_id=commonNameToSANDefaultImpl\npolicyset.serverCertSet.9.default.name=copy CN to SAN Default\nprofileId=caCMCECserverCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:17Z DEBUG response status 409 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:16 GMT 2019-01-17T11:04:17Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:17Z DEBUG Error migrating 'caCMCECserverCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:17Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caCMCECserverCert?action=enable 2019-01-17T11:04:17Z DEBUG request body '' 2019-01-17T11:04:17Z DEBUG response status 500 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6520 Date: Thu, 17 Jan 2019 11:04:16 GMT Connection: close 2019-01-17T11:04:17Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)\n\tsun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)\n\tsun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)\n\tsun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)\n\tsun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:17Z DEBUG Failed to enable profile 'caCMCECserverCert' (it is probably already enabled) 2019-01-17T11:04:17Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:17Z DEBUG request body '' 2019-01-17T11:04:17Z DEBUG response status 204 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=968191B6F2938CD69EA2A679B1D13647; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:16 GMT 2019-01-17T11:04:17Z DEBUG response body '' 2019-01-17T11:04:17Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:17Z DEBUG request body '' 2019-01-17T11:04:17Z DEBUG response status 200 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=D9402F3D1FA38B0361B786036DA21B56; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:16 GMT 2019-01-17T11:04:17Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:17Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:17Z DEBUG request body 'desc=This certificate profile is for enrolling subsystem certificates with ECC keys using CMC.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=CMCAuth\nauthz.acl=group="Certificate Manager Agents"\nname=Subsystem Certificate Enrollment with ECC keys using CMC\ninput.list=i1\ninput.i1.class_id=cmcCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=720\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=720\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=EC\npolicyset.serverCertSet.3.constraint.params.keyParameters=nistp256,nistp384,nistp521\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\nprofileId=caCMCECsubsystemCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:17Z DEBUG response status 409 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:16 GMT 2019-01-17T11:04:17Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:17Z DEBUG Error migrating 'caCMCECsubsystemCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:17Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caCMCECsubsystemCert?action=enable 2019-01-17T11:04:17Z DEBUG request body '' 2019-01-17T11:04:17Z DEBUG response status 500 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6520 Date: Thu, 17 Jan 2019 11:04:16 GMT Connection: close 2019-01-17T11:04:17Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)\n\tsun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)\n\tsun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)\n\tsun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)\n\tsun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:17Z DEBUG Failed to enable profile 'caCMCECsubsystemCert' (it is probably already enabled) 2019-01-17T11:04:17Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:17Z DEBUG request body '' 2019-01-17T11:04:17Z DEBUG response status 204 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=BED3EB52F719BE7E96642043BF875FA0; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:16 GMT 2019-01-17T11:04:17Z DEBUG response body '' 2019-01-17T11:04:17Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:17Z DEBUG request body '' 2019-01-17T11:04:17Z DEBUG response status 200 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=FE83B41EDBE30B0BB1D99A4746E0AE00; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:16 GMT 2019-01-17T11:04:17Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:17Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:17Z DEBUG request body 'desc=This certificate profile is for enrolling subsystem certificates using CMC.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=CMCAuth\nauthz.acl=group="Certificate Manager Agents"\nname=Subsystem Certificate Enrollment using CMC\ninput.list=i1\ninput.i1.class_id=cmcCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=720\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=720\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\nprofileId=caCMCsubsystemCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:17Z DEBUG response status 409 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:16 GMT 2019-01-17T11:04:17Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:17Z DEBUG Error migrating 'caCMCsubsystemCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:17Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caCMCsubsystemCert?action=enable 2019-01-17T11:04:17Z DEBUG request body '' 2019-01-17T11:04:17Z DEBUG response status 500 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6520 Date: Thu, 17 Jan 2019 11:04:16 GMT Connection: close 2019-01-17T11:04:17Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)\n\tsun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)\n\tsun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)\n\tsun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)\n\tsun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:17Z DEBUG Failed to enable profile 'caCMCsubsystemCert' (it is probably already enabled) 2019-01-17T11:04:17Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:17Z DEBUG request body '' 2019-01-17T11:04:17Z DEBUG response status 204 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=0B5AF93F400FC1EB0B78322F99602DB6; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:16 GMT 2019-01-17T11:04:17Z DEBUG response body '' 2019-01-17T11:04:17Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:17Z DEBUG request body '' 2019-01-17T11:04:17Z DEBUG response status 200 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=47754B5C0167783FB353A63C550706FA; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:16 GMT 2019-01-17T11:04:17Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:17Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:17Z DEBUG request body 'desc=This certificate profile is for enrolling audit signing certificates using CMC.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=CMCAuth\nauthz.acl=group="Certificate Manager Agents"\nname=Audit Signing Certificate Enrollment using CMC\ninput.list=i1\ninput.i1.class_id=cmcCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=auditSigningCertSet\npolicyset.auditSigningCertSet.list=1,2,3,4,5,6,9\npolicyset.auditSigningCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.auditSigningCertSet.1.constraint.name=Subject Name Constraint\npolicyset.auditSigningCertSet.1.constraint.params.pattern=CN=.*\npolicyset.auditSigningCertSet.1.constraint.params.accept=true\npolicyset.auditSigningCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.auditSigningCertSet.1.default.name=Subject Name Default\npolicyset.auditSigningCertSet.1.default.params.name=\npolicyset.auditSigningCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.auditSigningCertSet.2.constraint.name=Validity Constraint\npolicyset.auditSigningCertSet.2.constraint.params.range=720\npolicyset.auditSigningCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.auditSigningCertSet.2.constraint.params.notAfterCheck=false\npolicyset.auditSigningCertSet.2.default.class_id=validityDefaultImpl\npolicyset.auditSigningCertSet.2.default.name=Validity Default\npolicyset.auditSigningCertSet.2.default.params.range=720\npolicyset.auditSigningCertSet.2.default.params.startTime=0\npolicyset.auditSigningCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.auditSigningCertSet.3.constraint.name=Key Constraint\npolicyset.auditSigningCertSet.3.constraint.params.keyType=-\npolicyset.auditSigningCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,nistp256,nistp521\npolicyset.auditSigningCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.auditSigningCertSet.3.default.name=Key Default\npolicyset.auditSigningCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.auditSigningCertSet.4.constraint.name=No Constraint\npolicyset.auditSigningCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.auditSigningCertSet.4.default.name=Authority Key Identifier Default\npolicyset.auditSigningCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.auditSigningCertSet.5.constraint.name=No Constraint\npolicyset.auditSigningCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.auditSigningCertSet.5.default.name=AIA Extension Default\npolicyset.auditSigningCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.auditSigningCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.auditSigningCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.auditSigningCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.auditSigningCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.auditSigningCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.auditSigningCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.auditSigningCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.auditSigningCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.auditSigningCertSet.6.default.name=Key Usage Default\npolicyset.auditSigningCertSet.6.default.params.keyUsageCritical=true\npolicyset.auditSigningCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.auditSigningCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.auditSigningCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.auditSigningCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.auditSigningCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.auditSigningCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.auditSigningCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.auditSigningCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.auditSigningCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.auditSigningCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.auditSigningCertSet.9.constraint.name=No Constraint\npolicyset.auditSigningCertSet.9.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.auditSigningCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.auditSigningCertSet.9.default.name=Signing Alg\npolicyset.auditSigningCertSet.9.default.params.signingAlg=-\nprofileId=caCMCauditSigningCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:17Z DEBUG response status 409 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:16 GMT 2019-01-17T11:04:17Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:17Z DEBUG Error migrating 'caCMCauditSigningCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:17Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caCMCauditSigningCert?action=enable 2019-01-17T11:04:17Z DEBUG request body '' 2019-01-17T11:04:17Z DEBUG response status 500 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:16 GMT Connection: close 2019-01-17T11:04:17Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:17Z DEBUG Failed to enable profile 'caCMCauditSigningCert' (it is probably already enabled) 2019-01-17T11:04:17Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:17Z DEBUG request body '' 2019-01-17T11:04:17Z DEBUG response status 204 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=A7065C65A9D170D01BB62B0BE8E4D123; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:17Z DEBUG response body '' 2019-01-17T11:04:17Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:17Z DEBUG request body '' 2019-01-17T11:04:17Z DEBUG response status 200 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=7A827AC7F4A81D4A8CEDC8C9CCE86C9C; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:17Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:17Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:17Z DEBUG request body 'desc=This certificate profile is for enrolling Certificate Authority certificates using CMC.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=CMCAuth\nauthz.acl=group="Certificate Manager Agents"\nname=Certificate Manager Signing Certificate Enrollment using CMC\ninput.list=i1\ninput.i1.class_id=cmcCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=caCertSet\npolicyset.caCertSet.list=1,2,3,4,5,6,8,9,10\npolicyset.caCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.caCertSet.1.constraint.name=Subject Name Constraint\npolicyset.caCertSet.1.constraint.params.pattern=CN=.*\npolicyset.caCertSet.1.constraint.params.accept=true\npolicyset.caCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.caCertSet.1.default.name=Subject Name Default\npolicyset.caCertSet.1.default.params.name=\npolicyset.caCertSet.2.constraint.class_id=caValidityConstraintImpl\npolicyset.caCertSet.2.constraint.name=CA Validity Constraint\npolicyset.caCertSet.2.constraint.params.range=7305\npolicyset.caCertSet.2.default.class_id=caValidityDefaultImpl\npolicyset.caCertSet.2.default.name=CA Certificate Validity Default\npolicyset.caCertSet.2.default.params.range=7305\npolicyset.caCertSet.2.default.params.startTime=0\npolicyset.caCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.caCertSet.3.constraint.name=Key Constraint\npolicyset.caCertSet.3.constraint.params.keyType=-\npolicyset.caCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,nistp256,nistp384,nistp521\npolicyset.caCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.caCertSet.3.default.name=Key Default\npolicyset.caCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.caCertSet.4.constraint.name=No Constraint\npolicyset.caCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.caCertSet.4.default.name=Authority Key Identifier Default\npolicyset.caCertSet.5.constraint.class_id=basicConstraintsExtConstraintImpl\npolicyset.caCertSet.5.constraint.name=Basic Constraint Extension Constraint\npolicyset.caCertSet.5.constraint.params.basicConstraintsCritical=true\npolicyset.caCertSet.5.constraint.params.basicConstraintsIsCA=true\npolicyset.caCertSet.5.constraint.params.basicConstraintsMinPathLen=-1\npolicyset.caCertSet.5.constraint.params.basicConstraintsMaxPathLen=-1\npolicyset.caCertSet.5.default.class_id=basicConstraintsExtDefaultImpl\npolicyset.caCertSet.5.default.name=Basic Constraints Extension Default\npolicyset.caCertSet.5.default.params.basicConstraintsCritical=true\npolicyset.caCertSet.5.default.params.basicConstraintsIsCA=true\npolicyset.caCertSet.5.default.params.basicConstraintsPathLen=-1\npolicyset.caCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.caCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.caCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.caCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.caCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.caCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.caCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.caCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.caCertSet.6.constraint.params.keyUsageKeyCertSign=true\npolicyset.caCertSet.6.constraint.params.keyUsageCrlSign=true\npolicyset.caCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.caCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.caCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.caCertSet.6.default.name=Key Usage Default\npolicyset.caCertSet.6.default.params.keyUsageCritical=true\npolicyset.caCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.caCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.caCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.caCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.caCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.caCertSet.6.default.params.keyUsageKeyCertSign=true\npolicyset.caCertSet.6.default.params.keyUsageCrlSign=true\npolicyset.caCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.caCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.caCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.caCertSet.8.constraint.name=No Constraint\npolicyset.caCertSet.8.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.caCertSet.8.default.name=Subject Key Identifier Extension Default\npolicyset.caCertSet.8.default.params.critical=false\npolicyset.caCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.caCertSet.9.constraint.name=No Constraint\npolicyset.caCertSet.9.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.caCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.caCertSet.9.default.name=Signing Alg\npolicyset.caCertSet.9.default.params.signingAlg=-\npolicyset.caCertSet.10.constraint.class_id=noConstraintImpl\npolicyset.caCertSet.10.constraint.name=No Constraint\npolicyset.caCertSet.10.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.caCertSet.10.default.name=AIA Extension Default\npolicyset.caCertSet.10.default.params.authInfoAccessADEnable_0=true\npolicyset.caCertSet.10.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.caCertSet.10.default.params.authInfoAccessADLocation_0=\npolicyset.caCertSet.10.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.caCertSet.10.default.params.authInfoAccessCritical=false\npolicyset.caCertSet.10.default.params.authInfoAccessNumADs=1\nprofileId=caCMCcaCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:17Z DEBUG response status 409 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:17Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:17Z DEBUG Error migrating 'caCMCcaCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:17Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caCMCcaCert?action=enable 2019-01-17T11:04:17Z DEBUG request body '' 2019-01-17T11:04:17Z DEBUG response status 500 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:17 GMT Connection: close 2019-01-17T11:04:17Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:17Z DEBUG Failed to enable profile 'caCMCcaCert' (it is probably already enabled) 2019-01-17T11:04:17Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:17Z DEBUG request body '' 2019-01-17T11:04:17Z DEBUG response status 204 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=8961112C3D376709B04D65418E8C0D32; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:17Z DEBUG response body '' 2019-01-17T11:04:17Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:17Z DEBUG request body '' 2019-01-17T11:04:17Z DEBUG response status 200 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=E424000A442924BB342C47BE853C8B7A; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:17Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:17Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:17Z DEBUG request body 'desc=This certificate profile is for enrolling OCSP Responder signing certificates using CMC.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=CMCAuth\nauthz.acl=group="Certificate Manager Agents"\nname=OCSP Responder Signing Certificate Enrollment using CMC\ninput.list=i1\ninput.i1.class_id=cmcCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=ocspCertSet\npolicyset.ocspCertSet.list=1,2,3,4,5,6,8,9\npolicyset.ocspCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.ocspCertSet.1.constraint.name=Subject Name Constraint\npolicyset.ocspCertSet.1.constraint.params.pattern=CN=.*\npolicyset.ocspCertSet.1.constraint.params.accept=true\npolicyset.ocspCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.ocspCertSet.1.default.name=Subject Name Default\npolicyset.ocspCertSet.1.default.params.name=\npolicyset.ocspCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.ocspCertSet.2.constraint.name=Validity Constraint\npolicyset.ocspCertSet.2.constraint.params.range=720\npolicyset.ocspCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.ocspCertSet.2.constraint.params.notAfterCheck=false\npolicyset.ocspCertSet.2.default.class_id=validityDefaultImpl\npolicyset.ocspCertSet.2.default.name=Validity Default\npolicyset.ocspCertSet.2.default.params.range=720\npolicyset.ocspCertSet.2.default.params.startTime=0\npolicyset.ocspCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.ocspCertSet.3.constraint.name=Key Constraint\npolicyset.ocspCertSet.3.constraint.params.keyType=-\npolicyset.ocspCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,nistp256,nistp384,nistp521\npolicyset.ocspCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.ocspCertSet.3.default.name=Key Default\npolicyset.ocspCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.ocspCertSet.4.constraint.name=No Constraint\npolicyset.ocspCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.ocspCertSet.4.default.name=Authority Key Identifier Default\npolicyset.ocspCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.ocspCertSet.5.constraint.name=No Constraint\npolicyset.ocspCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.ocspCertSet.5.default.name=AIA Extension Default\npolicyset.ocspCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.ocspCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.ocspCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.ocspCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.ocspCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.ocspCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.ocspCertSet.6.constraint.class_id=extendedKeyUsageExtConstraintImpl\npolicyset.ocspCertSet.6.constraint.name=Extended Key Usage Extension\npolicyset.ocspCertSet.6.constraint.params.exKeyUsageCritical=false\npolicyset.ocspCertSet.6.constraint.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.9\npolicyset.ocspCertSet.6.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.ocspCertSet.6.default.name=Extended Key Usage Default\npolicyset.ocspCertSet.6.default.params.exKeyUsageCritical=false\npolicyset.ocspCertSet.6.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.9\npolicyset.ocspCertSet.8.constraint.class_id=extensionConstraintImpl\npolicyset.ocspCertSet.8.constraint.name=No Constraint\npolicyset.ocspCertSet.8.constraint.params.extCritical=false\npolicyset.ocspCertSet.8.constraint.params.extOID=1.3.6.1.5.5.7.48.1.5\npolicyset.ocspCertSet.8.default.class_id=ocspNoCheckExtDefaultImpl\npolicyset.ocspCertSet.8.default.name=OCSP No Check Extension\npolicyset.ocspCertSet.8.default.params.ocspNoCheckCritical=false\npolicyset.ocspCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.ocspCertSet.9.constraint.name=No Constraint\npolicyset.ocspCertSet.9.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.ocspCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.ocspCertSet.9.default.name=Signing Alg\npolicyset.ocspCertSet.9.default.params.signingAlg=-\nprofileId=caCMCocspCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:17Z DEBUG response status 409 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:17Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:17Z DEBUG Error migrating 'caCMCocspCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:17Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caCMCocspCert?action=enable 2019-01-17T11:04:17Z DEBUG request body '' 2019-01-17T11:04:17Z DEBUG response status 500 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:17 GMT Connection: close 2019-01-17T11:04:17Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:17Z DEBUG Failed to enable profile 'caCMCocspCert' (it is probably already enabled) 2019-01-17T11:04:17Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:17Z DEBUG request body '' 2019-01-17T11:04:17Z DEBUG response status 204 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=81E387C85425193FBCB6736F0D9BBF74; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:17Z DEBUG response body '' 2019-01-17T11:04:17Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:17Z DEBUG request body '' 2019-01-17T11:04:17Z DEBUG response status 200 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=A3FF2F2F82C0F15B90CE4C3396FEE6DB; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:17Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:17Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:17Z DEBUG request body 'desc=This certificate profile is for enrolling Key Archival Authority transport certificates using CMC.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=CMCAuth\nauthz.acl=group="Certificate Manager Agents"\nname=Key Archival Authority Transport Certificate Enrollment using CMC\ninput.list=i1\ninput.i1.class_id=cmcCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=transportCertSet\npolicyset.transportCertSet.list=1,2,3,4,5,6,7,8\npolicyset.transportCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.transportCertSet.1.constraint.name=Subject Name Constraint\npolicyset.transportCertSet.1.constraint.params.pattern=CN=.*\npolicyset.transportCertSet.1.constraint.params.accept=true\npolicyset.transportCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.transportCertSet.1.default.name=Subject Name Default\npolicyset.transportCertSet.1.default.params.name=\npolicyset.transportCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.transportCertSet.2.constraint.name=Validity Constraint\npolicyset.transportCertSet.2.constraint.params.range=720\npolicyset.transportCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.transportCertSet.2.constraint.params.notAfterCheck=false\npolicyset.transportCertSet.2.default.class_id=validityDefaultImpl\npolicyset.transportCertSet.2.default.name=Validity Default\npolicyset.transportCertSet.2.default.params.range=720\npolicyset.transportCertSet.2.default.params.startTime=0\npolicyset.transportCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.transportCertSet.3.constraint.name=Key Constraint\npolicyset.transportCertSet.3.constraint.params.keyType=RSA\npolicyset.transportCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.transportCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.transportCertSet.3.default.name=Key Default\npolicyset.transportCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.transportCertSet.4.constraint.name=No Constraint\npolicyset.transportCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.transportCertSet.4.default.name=Authority Key Identifier Default\npolicyset.transportCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.transportCertSet.5.constraint.name=No Constraint\npolicyset.transportCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.transportCertSet.5.default.name=AIA Extension Default\npolicyset.transportCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.transportCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.transportCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.transportCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.transportCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.transportCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.transportCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.transportCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.transportCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.transportCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.transportCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.transportCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.transportCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.transportCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.transportCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.transportCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.transportCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.transportCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.transportCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.transportCertSet.6.default.name=Key Usage Default\npolicyset.transportCertSet.6.default.params.keyUsageCritical=true\npolicyset.transportCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.transportCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.transportCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.transportCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.transportCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.transportCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.transportCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.transportCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.transportCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.transportCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.transportCertSet.7.constraint.name=No Constraint\npolicyset.transportCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.transportCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.transportCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.transportCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2\npolicyset.transportCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.transportCertSet.8.constraint.name=No Constraint\npolicyset.transportCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.transportCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.transportCertSet.8.default.name=Signing Alg\npolicyset.transportCertSet.8.default.params.signingAlg=-\nprofileId=caCMCkraTransportCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:17Z DEBUG response status 409 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:17Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:17Z DEBUG Error migrating 'caCMCkraTransportCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:17Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caCMCkraTransportCert?action=enable 2019-01-17T11:04:17Z DEBUG request body '' 2019-01-17T11:04:17Z DEBUG response status 500 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:17 GMT Connection: close 2019-01-17T11:04:17Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:17Z DEBUG Failed to enable profile 'caCMCkraTransportCert' (it is probably already enabled) 2019-01-17T11:04:17Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:17Z DEBUG request body '' 2019-01-17T11:04:17Z DEBUG response status 204 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=C4A85B78C4C25B37926D1C69867017FC; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:17Z DEBUG response body '' 2019-01-17T11:04:17Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:17Z DEBUG request body '' 2019-01-17T11:04:17Z DEBUG response status 200 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=3A5F89428E777522413CDAA6256DDB32; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:17Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:17Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:17Z DEBUG request body 'desc=This certificate profile is for enrolling KRA storage certificates using CMC\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=CMCAuth\nauthz.acl=group="Certificate Manager Agents"\nname=KRA storage Certificate Enrollment using CMC\ninput.list=i1\ninput.i1.class_id=cmcCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=drmStorageCertSet\npolicyset.drmStorageCertSet.list=1,2,3,4,5,6,7,9\npolicyset.drmStorageCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.drmStorageCertSet.1.constraint.name=Subject Name Constraint\npolicyset.drmStorageCertSet.1.constraint.params.pattern=CN=.*\npolicyset.drmStorageCertSet.1.constraint.params.accept=true\npolicyset.drmStorageCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.drmStorageCertSet.1.default.name=Subject Name Default\npolicyset.drmStorageCertSet.1.default.params.name=\npolicyset.drmStorageCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.drmStorageCertSet.2.constraint.name=Validity Constraint\npolicyset.drmStorageCertSet.2.constraint.params.range=720\npolicyset.drmStorageCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.drmStorageCertSet.2.constraint.params.notAfterCheck=false\npolicyset.drmStorageCertSet.2.default.class_id=validityDefaultImpl\npolicyset.drmStorageCertSet.2.default.name=Validity Default\npolicyset.drmStorageCertSet.2.default.params.range=720\npolicyset.drmStorageCertSet.2.default.params.startTime=0\npolicyset.drmStorageCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.drmStorageCertSet.3.constraint.name=Key Constraint\npolicyset.drmStorageCertSet.3.constraint.params.keyType=RSA\npolicyset.drmStorageCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.drmStorageCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.drmStorageCertSet.3.default.name=Key Default\npolicyset.drmStorageCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.drmStorageCertSet.4.constraint.name=No Constraint\npolicyset.drmStorageCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.drmStorageCertSet.4.default.name=Authority Key Identifier Default\npolicyset.drmStorageCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.drmStorageCertSet.5.constraint.name=No Constraint\npolicyset.drmStorageCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.drmStorageCertSet.5.default.name=AIA Extension Default\npolicyset.drmStorageCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.drmStorageCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.drmStorageCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.drmStorageCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.drmStorageCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.drmStorageCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.drmStorageCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.drmStorageCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.drmStorageCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.drmStorageCertSet.6.default.name=Key Usage Default\npolicyset.drmStorageCertSet.6.default.params.keyUsageCritical=true\npolicyset.drmStorageCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.drmStorageCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.drmStorageCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.drmStorageCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.drmStorageCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.drmStorageCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.drmStorageCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.drmStorageCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.drmStorageCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.drmStorageCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.drmStorageCertSet.7.constraint.name=No Constraint\npolicyset.drmStorageCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.drmStorageCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.drmStorageCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.drmStorageCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2\npolicyset.drmStorageCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.drmStorageCertSet.9.constraint.name=No Constraint\npolicyset.drmStorageCertSet.9.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.drmStorageCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.drmStorageCertSet.9.default.name=Signing Alg\npolicyset.drmStorageCertSet.9.default.params.signingAlg=-\nprofileId=caCMCkraStorageCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:17Z DEBUG response status 409 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:17Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:17Z DEBUG Error migrating 'caCMCkraStorageCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:17Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caCMCkraStorageCert?action=enable 2019-01-17T11:04:17Z DEBUG request body '' 2019-01-17T11:04:17Z DEBUG response status 500 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:17 GMT Connection: close 2019-01-17T11:04:17Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:17Z DEBUG Failed to enable profile 'caCMCkraStorageCert' (it is probably already enabled) 2019-01-17T11:04:17Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:17Z DEBUG request body '' 2019-01-17T11:04:17Z DEBUG response status 204 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=39A7A5EDD1E45FE916467ED758BC23DB; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:17Z DEBUG response body '' 2019-01-17T11:04:17Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:17Z DEBUG request body '' 2019-01-17T11:04:17Z DEBUG response status 200 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=C542459F3AA6C2C77325D1075996C3FC; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:17Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:17Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:17Z DEBUG request body 'desc=This certificate profile is for enrolling user certificates.\nvisible=true\nenable=true\nenableBy=admin\nname=Manual User Dual-Use Certificate Enrollment\nauth.class_id=\ninput.list=i1,i2,i3\ninput.i1.class_id=keyGenInputImpl\ninput.i2.class_id=subjectNameInputImpl\ninput.i3.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=userCertSet\npolicyset.userCertSet.list=1,10,2,3,4,5,6,7,8,9\npolicyset.userCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.userCertSet.1.constraint.name=Subject Name Constraint\npolicyset.userCertSet.1.constraint.params.pattern=UID=.*\npolicyset.userCertSet.1.constraint.params.accept=true\npolicyset.userCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.userCertSet.1.default.name=Subject Name Default\npolicyset.userCertSet.1.default.params.name=\npolicyset.userCertSet.10.constraint.class_id=renewGracePeriodConstraintImpl\npolicyset.userCertSet.10.constraint.name=Renewal Grace Period Constraint\npolicyset.userCertSet.10.constraint.params.renewal.graceBefore=30\npolicyset.userCertSet.10.constraint.params.renewal.graceAfter=30\npolicyset.userCertSet.10.default.class_id=noDefaultImpl\npolicyset.userCertSet.10.default.name=No Default\npolicyset.userCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.userCertSet.2.constraint.name=Validity Constraint\npolicyset.userCertSet.2.constraint.params.range=365\npolicyset.userCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.userCertSet.2.constraint.params.notAfterCheck=false\npolicyset.userCertSet.2.default.class_id=validityDefaultImpl\npolicyset.userCertSet.2.default.name=Validity Default\npolicyset.userCertSet.2.default.params.range=180\npolicyset.userCertSet.2.default.params.startTime=0\npolicyset.userCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.userCertSet.3.constraint.name=Key Constraint\npolicyset.userCertSet.3.constraint.params.keyType=RSA\npolicyset.userCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.userCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.userCertSet.3.default.name=Key Default\npolicyset.userCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.4.constraint.name=No Constraint\npolicyset.userCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.userCertSet.4.default.name=Authority Key Identifier Default\npolicyset.userCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.5.constraint.name=No Constraint\npolicyset.userCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.userCertSet.5.default.name=AIA Extension Default\npolicyset.userCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.userCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.userCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.userCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.userCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.userCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.userCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.userCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.userCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.userCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.userCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.userCertSet.6.default.name=Key Usage Default\npolicyset.userCertSet.6.default.params.keyUsageCritical=true\npolicyset.userCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.userCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.userCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.userCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.7.constraint.name=No Constraint\npolicyset.userCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.userCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.userCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.userCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.userCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.8.constraint.name=No Constraint\npolicyset.userCertSet.8.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.userCertSet.8.default.name=Subject Alt Name Constraint\npolicyset.userCertSet.8.default.params.subjAltNameExtCritical=false\npolicyset.userCertSet.8.default.params.subjAltExtType_0=RFC822Name\npolicyset.userCertSet.8.default.params.subjAltExtPattern_0=$request.requestor_email$\npolicyset.userCertSet.8.default.params.subjAltExtGNEnable_0=true\npolicyset.userCertSet.8.default.params.subjAltNameNumGNs=1\npolicyset.userCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.userCertSet.9.constraint.name=No Constraint\npolicyset.userCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.userCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.userCertSet.9.default.name=Signing Alg\npolicyset.userCertSet.9.default.params.signingAlg=-\nprofileId=caUserCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:17Z DEBUG response status 409 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:17Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:17Z DEBUG Error migrating 'caUserCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:17Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caUserCert?action=enable 2019-01-17T11:04:17Z DEBUG request body '' 2019-01-17T11:04:17Z DEBUG response status 500 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:17 GMT Connection: close 2019-01-17T11:04:17Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:17Z DEBUG Failed to enable profile 'caUserCert' (it is probably already enabled) 2019-01-17T11:04:17Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:17Z DEBUG request body '' 2019-01-17T11:04:17Z DEBUG response status 204 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=331C4529AF831CF05997088AFA6137D7; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:17Z DEBUG response body '' 2019-01-17T11:04:17Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:17Z DEBUG request body '' 2019-01-17T11:04:17Z DEBUG response status 200 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=F14E3778CBB31092F9B5FC2FFFEC584F; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:17Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:17Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:17Z DEBUG request body 'desc=This certificate profile is for enrolling user ECC certificates.\nvisible=false\nenable=true\nenableBy=admin\nname=Manual User Dual-Use ECC Certificate Enrollment\nauth.class_id=\ninput.list=i1,i2,i3\ninput.i1.class_id=keyGenInputImpl\ninput.i2.class_id=subjectNameInputImpl\ninput.i3.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=userCertSet\npolicyset.userCertSet.list=1,10,2,3,4,5,6,7,8,9\npolicyset.userCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.userCertSet.1.constraint.name=Subject Name Constraint\npolicyset.userCertSet.1.constraint.params.pattern=UID=.*\npolicyset.userCertSet.1.constraint.params.accept=true\npolicyset.userCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.userCertSet.1.default.name=Subject Name Default\npolicyset.userCertSet.1.default.params.name=\npolicyset.userCertSet.10.constraint.class_id=renewGracePeriodConstraintImpl\npolicyset.userCertSet.10.constraint.name=Renewal Grace Period Constraint\npolicyset.userCertSet.10.constraint.params.renewal.graceBefore=30\npolicyset.userCertSet.10.constraint.params.renewal.graceAfter=30\npolicyset.userCertSet.10.default.class_id=noDefaultImpl\npolicyset.userCertSet.10.default.name=No Default\npolicyset.userCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.userCertSet.2.constraint.name=Validity Constraint\npolicyset.userCertSet.2.constraint.params.range=365\npolicyset.userCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.userCertSet.2.constraint.params.notAfterCheck=false\npolicyset.userCertSet.2.default.class_id=validityDefaultImpl\npolicyset.userCertSet.2.default.name=Validity Default\npolicyset.userCertSet.2.default.params.range=180\npolicyset.userCertSet.2.default.params.startTime=0\npolicyset.userCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.userCertSet.3.constraint.name=Key Constraint\npolicyset.userCertSet.3.constraint.params.keyType=EC\npolicyset.userCertSet.3.constraint.params.keyParameters=nistp256,nistp384,nistp521\npolicyset.userCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.userCertSet.3.default.name=Key Default\npolicyset.userCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.4.constraint.name=No Constraint\npolicyset.userCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.userCertSet.4.default.name=Authority Key Identifier Default\npolicyset.userCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.5.constraint.name=No Constraint\npolicyset.userCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.userCertSet.5.default.name=AIA Extension Default\npolicyset.userCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.userCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.userCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.userCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.userCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.userCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.userCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.userCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.userCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.userCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.userCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyAgreement=true\npolicyset.userCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.userCertSet.6.default.name=Key Usage Default\npolicyset.userCertSet.6.default.params.keyUsageCritical=true\npolicyset.userCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.userCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.userCertSet.6.default.params.keyUsageKeyAgreement=true\npolicyset.userCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.7.constraint.name=No Constraint\npolicyset.userCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.userCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.userCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.userCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.userCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.8.constraint.name=No Constraint\npolicyset.userCertSet.8.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.userCertSet.8.default.name=Subject Alt Name Constraint\npolicyset.userCertSet.8.default.params.subjAltNameExtCritical=false\npolicyset.userCertSet.8.default.params.subjAltExtType_0=RFC822Name\npolicyset.userCertSet.8.default.params.subjAltExtPattern_0=$request.requestor_email$\npolicyset.userCertSet.8.default.params.subjAltExtGNEnable_0=true\npolicyset.userCertSet.8.default.params.subjAltNameNumGNs=1\npolicyset.userCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.userCertSet.9.constraint.name=No Constraint\npolicyset.userCertSet.9.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.userCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.userCertSet.9.default.name=Signing Alg\npolicyset.userCertSet.9.default.params.signingAlg=-\nprofileId=caECUserCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:17Z DEBUG response status 409 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:17Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:17Z DEBUG Error migrating 'caECUserCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:17Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caECUserCert?action=enable 2019-01-17T11:04:17Z DEBUG request body '' 2019-01-17T11:04:17Z DEBUG response status 500 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:17 GMT Connection: close 2019-01-17T11:04:17Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:17Z DEBUG Failed to enable profile 'caECUserCert' (it is probably already enabled) 2019-01-17T11:04:17Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:17Z DEBUG request body '' 2019-01-17T11:04:17Z DEBUG response status 204 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=0A25E59C8D47CBE0140923CB19DA25C0; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:17Z DEBUG response body '' 2019-01-17T11:04:17Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:17Z DEBUG request body '' 2019-01-17T11:04:17Z DEBUG response status 200 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=7254E8FD7EFB9C1051F7658C1922D719; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:17Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:17Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:17Z DEBUG request body 'desc=This certificate profile is for enrolling user certificates with S/MIME capabilities extension - OID: 1.2.840.113549.1.9.15\nvisible=true\nenable=true\nenableBy=admin\nname=Manual User Dual-Use S/MIME capabilities Certificate Enrollment\nauth.class_id=\ninput.list=i1,i2,i3\ninput.i1.class_id=keyGenInputImpl\ninput.i2.class_id=subjectNameInputImpl\ninput.i3.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=userCertSet\npolicyset.userCertSet.list=1,10,2,3,4,5,6,7,8,9,11\npolicyset.userCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.userCertSet.1.constraint.name=Subject Name Constraint\npolicyset.userCertSet.1.constraint.params.pattern=UID=.*\npolicyset.userCertSet.1.constraint.params.accept=true\npolicyset.userCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.userCertSet.1.default.name=Subject Name Default\npolicyset.userCertSet.1.default.params.name=\npolicyset.userCertSet.10.constraint.class_id=renewGracePeriodConstraintImpl\npolicyset.userCertSet.10.constraint.name=Renewal Grace Period Constraint\npolicyset.userCertSet.10.constraint.params.renewal.graceBefore=30\npolicyset.userCertSet.10.constraint.params.renewal.graceAfter=30\npolicyset.userCertSet.10.default.class_id=noDefaultImpl\npolicyset.userCertSet.10.default.name=No Default\npolicyset.userCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.userCertSet.2.constraint.name=Validity Constraint\npolicyset.userCertSet.2.constraint.params.range=365\npolicyset.userCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.userCertSet.2.constraint.params.notAfterCheck=false\npolicyset.userCertSet.2.default.class_id=validityDefaultImpl\npolicyset.userCertSet.2.default.name=Validity Default\npolicyset.userCertSet.2.default.params.range=180\npolicyset.userCertSet.2.default.params.startTime=0\npolicyset.userCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.userCertSet.3.constraint.name=Key Constraint\npolicyset.userCertSet.3.constraint.params.keyType=-\npolicyset.userCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,nistp256,nistp384,nistp521\npolicyset.userCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.userCertSet.3.default.name=Key Default\npolicyset.userCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.4.constraint.name=No Constraint\npolicyset.userCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.userCertSet.4.default.name=Authority Key Identifier Default\npolicyset.userCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.5.constraint.name=No Constraint\npolicyset.userCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.userCertSet.5.default.name=AIA Extension Default\npolicyset.userCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.userCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.userCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.userCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.userCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.userCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.userCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.userCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.userCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.userCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.userCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.userCertSet.6.default.name=Key Usage Default\npolicyset.userCertSet.6.default.params.keyUsageCritical=true\npolicyset.userCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.userCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.userCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.userCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.7.constraint.name=No Constraint\npolicyset.userCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.userCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.userCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.userCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.userCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.8.constraint.name=No Constraint\npolicyset.userCertSet.8.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.userCertSet.8.default.name=Subject Alt Name Constraint\npolicyset.userCertSet.8.default.params.subjAltNameExtCritical=false\npolicyset.userCertSet.8.default.params.subjAltExtType_0=RFC822Name\npolicyset.userCertSet.8.default.params.subjAltExtPattern_0=$request.requestor_email$\npolicyset.userCertSet.8.default.params.subjAltExtGNEnable_0=true\npolicyset.userCertSet.8.default.params.subjAltNameNumGNs=1\npolicyset.userCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.userCertSet.9.constraint.name=No Constraint\npolicyset.userCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.userCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.userCertSet.9.default.name=Signing Alg\npolicyset.userCertSet.9.default.params.signingAlg=-\npolicyset.userCertSet.11.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.11.constraint.name=No Constraint\npolicyset.userCertSet.11.default.class_id=genericExtDefaultImpl\npolicyset.userCertSet.11.default.name=Generic Extension\npolicyset.userCertSet.11.default.params.genericExtOID=1.2.840.113549.1.9.15\npolicyset.userCertSet.11.default.params.genericExtData=3067300B06092A864886F70D010105300B06092A864886F70D01010B300B06092A864886F70D01010C300B06092A864886F70D01010D300A06082A864886F70D0307300B0609608648016503040102300B060960864801650304012A300B06092A864886F70D010101\nprofileId=caUserSMIMEcapCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:17Z DEBUG response status 409 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:17Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:17Z DEBUG Error migrating 'caUserSMIMEcapCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:17Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caUserSMIMEcapCert?action=enable 2019-01-17T11:04:17Z DEBUG request body '' 2019-01-17T11:04:17Z DEBUG response status 500 2019-01-17T11:04:17Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:17 GMT Connection: close 2019-01-17T11:04:17Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:17Z DEBUG Failed to enable profile 'caUserSMIMEcapCert' (it is probably already enabled) 2019-01-17T11:04:17Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:17Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 204 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=3F22E0A09D2BC60CC311CE396F47A1E3; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:18Z DEBUG response body '' 2019-01-17T11:04:18Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 200 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=274D171089C3CD9523718F5270162CB8; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:18Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:18Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:18Z DEBUG request body 'desc=This certificate profile is for enrolling dual user certificates. It works only with Netscape 7.0 or later.\nvisible=false\nenable=true\nenableBy=admin\nname=Manual User Signing & Encryption Certificates Enrollment\nauth.class_id=\ninput.list=i1,i2,i3\ninput.i1.class_id=dualKeyGenInputImpl\ninput.i2.class_id=subjectNameInputImpl\ninput.i3.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=encryptionCertSet,signingCertSet\npolicyset.encryptionCertSet.list=1,2,3,4,5,6,7,8,9\npolicyset.encryptionCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.encryptionCertSet.1.constraint.name=Subject Name Constraint\npolicyset.encryptionCertSet.1.constraint.params.pattern=UID=.*\npolicyset.encryptionCertSet.1.constraint.params.accept=true\npolicyset.encryptionCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.encryptionCertSet.1.default.name=Subject Name Default\npolicyset.encryptionCertSet.1.default.params.name=\npolicyset.encryptionCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.encryptionCertSet.2.constraint.name=Validity Constraint\npolicyset.encryptionCertSet.2.constraint.params.range=365\npolicyset.encryptionCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.encryptionCertSet.2.constraint.params.notAfterCheck=false\npolicyset.encryptionCertSet.2.default.class_id=validityDefaultImpl\npolicyset.encryptionCertSet.2.default.name=Validity Default\npolicyset.encryptionCertSet.2.default.params.range=180\npolicyset.encryptionCertSet.2.default.params.startTime=0\npolicyset.encryptionCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.encryptionCertSet.3.constraint.name=Key Constraint\npolicyset.encryptionCertSet.3.constraint.params.keyType=RSA\npolicyset.encryptionCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.encryptionCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.encryptionCertSet.3.default.name=Key Default\npolicyset.encryptionCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.encryptionCertSet.4.constraint.name=No Constraint\npolicyset.encryptionCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.encryptionCertSet.4.default.name=Authority Key Identifier Default\npolicyset.encryptionCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.encryptionCertSet.5.constraint.name=No Constraint\npolicyset.encryptionCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.encryptionCertSet.5.default.name=AIA Extension Default\npolicyset.encryptionCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.encryptionCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.encryptionCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.encryptionCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.encryptionCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.encryptionCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.encryptionCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.encryptionCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.encryptionCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.encryptionCertSet.6.constraint.params.keyUsageDigitalSignature=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageNonRepudiation=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.encryptionCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.encryptionCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.encryptionCertSet.6.default.name=Key Usage Default\npolicyset.encryptionCertSet.6.default.params.keyUsageCritical=true\npolicyset.encryptionCertSet.6.default.params.keyUsageDigitalSignature=false\npolicyset.encryptionCertSet.6.default.params.keyUsageNonRepudiation=false\npolicyset.encryptionCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.encryptionCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.encryptionCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.encryptionCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.encryptionCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.encryptionCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.encryptionCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.encryptionCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.encryptionCertSet.7.constraint.name=No Constraint\npolicyset.encryptionCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.encryptionCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.encryptionCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.encryptionCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.encryptionCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.encryptionCertSet.8.constraint.name=No Constraint\npolicyset.encryptionCertSet.8.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.encryptionCertSet.8.default.name=Subject Alt Name Constraint\npolicyset.encryptionCertSet.8.default.params.subjAltNameExtCritical=false\npolicyset.encryptionCertSet.8.default.params.subjAltExtType_0=RFC822Name\npolicyset.encryptionCertSet.8.default.params.subjAltExtPattern_0=$request.requestor_email$\npolicyset.encryptionCertSet.8.default.params.subjAltExtGNEnable_0=true\npolicyset.encryptionCertSet.8.default.params.subjAltNameNumGNs=1\npolicyset.encryptionCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.encryptionCertSet.9.constraint.name=No Constraint\npolicyset.encryptionCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.encryptionCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.encryptionCertSet.9.default.name=Signing Alg\npolicyset.encryptionCertSet.9.default.params.signingAlg=-\npolicyset.signingCertSet.list=1,2,3,4,6,7,8,9\npolicyset.signingCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.signingCertSet.1.constraint.name=Subject Name Constraint\npolicyset.signingCertSet.1.constraint.params.pattern=UID=.*\npolicyset.signingCertSet.1.constraint.params.accept=true\npolicyset.signingCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.signingCertSet.1.default.name=Subject Name Default\npolicyset.signingCertSet.1.default.params.name=\npolicyset.signingCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.signingCertSet.2.constraint.name=Validity Constraint\npolicyset.signingCertSet.2.constraint.params.range=365\npolicyset.signingCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.signingCertSet.2.constraint.params.notAfterCheck=false\npolicyset.signingCertSet.2.default.class_id=validityDefaultImpl\npolicyset.signingCertSet.2.default.name=Validity Default\npolicyset.signingCertSet.2.default.params.range=180\npolicyset.signingCertSet.2.default.params.startTime=0\npolicyset.signingCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.signingCertSet.3.constraint.name=Key Constraint\npolicyset.signingCertSet.3.constraint.params.keyType=RSA\npolicyset.signingCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.signingCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.signingCertSet.3.default.name=Key Default\npolicyset.signingCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.signingCertSet.4.constraint.name=No Constraint\npolicyset.signingCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.signingCertSet.4.default.name=Authority Key Identifier Default\npolicyset.signingCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.signingCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.signingCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.signingCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.signingCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.signingCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.signingCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.signingCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.signingCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.signingCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.signingCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.signingCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.signingCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.signingCertSet.6.default.name=Key Usage Default\npolicyset.signingCertSet.6.default.params.keyUsageCritical=true\npolicyset.signingCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.signingCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.signingCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.signingCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.signingCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.signingCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.signingCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.signingCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.signingCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.signingCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.signingCertSet.7.constraint.name=No Constraint\npolicyset.signingCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.signingCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.signingCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.signingCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.signingCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.signingCertSet.8.constraint.name=No Constraint\npolicyset.signingCertSet.8.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.signingCertSet.8.default.name=Subject Alt Name Constraint\npolicyset.signingCertSet.8.default.params.subjAltNameExtCritical=false\npolicyset.signingCertSet.8.default.params.subjAltExtType_0=RFC822Name\npolicyset.signingCertSet.8.default.params.subjAltExtPattern_0=$request.requestor_email$\npolicyset.signingCertSet.8.default.params.subjAltExtGNEnable_0=true\npolicyset.signingCertSet.8.default.params.subjAltNameNumGNs=1\npolicyset.signingCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.signingCertSet.9.constraint.name=No Constraint\npolicyset.signingCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.signingCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.signingCertSet.9.default.name=Signing Alg\npolicyset.signingCertSet.9.default.params.signingAlg=-\npolicyset.signingCertSet.9.default.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\nprofileId=caDualCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:18Z DEBUG response status 409 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:18Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:18Z DEBUG Error migrating 'caDualCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:18Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caDualCert?action=enable 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 500 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:17 GMT Connection: close 2019-01-17T11:04:18Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:18Z DEBUG Failed to enable profile 'caDualCert' (it is probably already enabled) 2019-01-17T11:04:18Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 204 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=90DEB5C6E4CA36AC4F4AA2244415D20D; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:18Z DEBUG response body '' 2019-01-17T11:04:18Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 200 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=E74A746D9799CC6DE03752D676F47D7C; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:18Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:18Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:18Z DEBUG request body 'desc=This certificate profile is for enrolling dual user certificates. It works only with Netscape 7.0 or later.\nvisible=true\nenable=true\nenableBy=admin\nname=Directory-authenticated User Signing & Encryption Certificates Enrollment\nauth.instance_id=UserDirEnrollment\ninput.list=i1,i2,i3\ninput.i1.class_id=dualKeyGenInputImpl\ninput.i2.class_id=subjectNameInputImpl\ninput.i3.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=encryptionCertSet,signingCertSet\npolicyset.encryptionCertSet.list=1,2,3,4,5,6,7,8,9\npolicyset.encryptionCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.encryptionCertSet.1.constraint.name=Subject Name Constraint\npolicyset.encryptionCertSet.1.constraint.params.pattern=UID=.*\npolicyset.encryptionCertSet.1.constraint.params.accept=true\npolicyset.encryptionCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.encryptionCertSet.1.default.name=Subject Name Default\npolicyset.encryptionCertSet.1.default.params.name=\npolicyset.encryptionCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.encryptionCertSet.2.constraint.name=Validity Constraint\npolicyset.encryptionCertSet.2.constraint.params.range=365\npolicyset.encryptionCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.encryptionCertSet.2.constraint.params.notAfterCheck=false\npolicyset.encryptionCertSet.2.default.class_id=validityDefaultImpl\npolicyset.encryptionCertSet.2.default.name=Validity Default\npolicyset.encryptionCertSet.2.default.params.range=180\npolicyset.encryptionCertSet.2.default.params.startTime=0\npolicyset.encryptionCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.encryptionCertSet.3.constraint.name=Key Constraint\npolicyset.encryptionCertSet.3.constraint.params.keyType=RSA\npolicyset.encryptionCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.encryptionCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.encryptionCertSet.3.default.name=Key Default\npolicyset.encryptionCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.encryptionCertSet.4.constraint.name=No Constraint\npolicyset.encryptionCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.encryptionCertSet.4.default.name=Authority Key Identifier Default\npolicyset.encryptionCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.encryptionCertSet.5.constraint.name=No Constraint\npolicyset.encryptionCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.encryptionCertSet.5.default.name=AIA Extension Default\npolicyset.encryptionCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.encryptionCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.encryptionCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.encryptionCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.encryptionCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.encryptionCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.encryptionCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.encryptionCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.encryptionCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.encryptionCertSet.6.constraint.params.keyUsageDigitalSignature=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageNonRepudiation=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.encryptionCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.encryptionCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.encryptionCertSet.6.default.name=Key Usage Default\npolicyset.encryptionCertSet.6.default.params.keyUsageCritical=true\npolicyset.encryptionCertSet.6.default.params.keyUsageDigitalSignature=false\npolicyset.encryptionCertSet.6.default.params.keyUsageNonRepudiation=false\npolicyset.encryptionCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.encryptionCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.encryptionCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.encryptionCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.encryptionCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.encryptionCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.encryptionCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.encryptionCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.encryptionCertSet.7.constraint.name=No Constraint\npolicyset.encryptionCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.encryptionCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.encryptionCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.encryptionCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.encryptionCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.encryptionCertSet.8.constraint.name=No Constraint\npolicyset.encryptionCertSet.8.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.encryptionCertSet.8.default.name=Subject Alt Name Constraint\npolicyset.encryptionCertSet.8.default.params.subjAltNameExtCritical=false\npolicyset.encryptionCertSet.8.default.params.subjAltExtType_0=RFC822Name\npolicyset.encryptionCertSet.8.default.params.subjAltExtPattern_0=$request.requestor_email$\npolicyset.encryptionCertSet.8.default.params.subjAltExtGNEnable_0=true\npolicyset.encryptionCertSet.8.default.params.subjAltNameNumGNs=1\npolicyset.encryptionCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.encryptionCertSet.9.constraint.name=No Constraint\npolicyset.encryptionCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA384withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withEC,SHA512withEC\npolicyset.encryptionCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.encryptionCertSet.9.default.name=Signing Alg\npolicyset.encryptionCertSet.9.default.params.signingAlg=-\npolicyset.signingCertSet.list=1,2,3,4,6,7,8,9\npolicyset.signingCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.signingCertSet.1.constraint.name=Subject Name Constraint\npolicyset.signingCertSet.1.constraint.params.pattern=UID=.*\npolicyset.signingCertSet.1.constraint.params.accept=true\npolicyset.signingCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.signingCertSet.1.default.name=Subject Name Default\npolicyset.signingCertSet.1.default.params.name=\npolicyset.signingCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.signingCertSet.2.constraint.name=Validity Constraint\npolicyset.signingCertSet.2.constraint.params.range=365\npolicyset.signingCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.signingCertSet.2.constraint.params.notAfterCheck=false\npolicyset.signingCertSet.2.default.class_id=validityDefaultImpl\npolicyset.signingCertSet.2.default.name=Validity Default\npolicyset.signingCertSet.2.default.params.range=180\npolicyset.signingCertSet.2.default.params.startTime=0\npolicyset.signingCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.signingCertSet.3.constraint.name=Key Constraint\npolicyset.signingCertSet.3.constraint.params.keyType=RSA\npolicyset.signingCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.signingCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.signingCertSet.3.default.name=Key Default\npolicyset.signingCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.signingCertSet.4.constraint.name=No Constraint\npolicyset.signingCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.signingCertSet.4.default.name=Authority Key Identifier Default\npolicyset.signingCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.signingCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.signingCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.signingCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.signingCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.signingCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.signingCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.signingCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.signingCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.signingCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.signingCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.signingCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.signingCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.signingCertSet.6.default.name=Key Usage Default\npolicyset.signingCertSet.6.default.params.keyUsageCritical=true\npolicyset.signingCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.signingCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.signingCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.signingCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.signingCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.signingCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.signingCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.signingCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.signingCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.signingCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.signingCertSet.7.constraint.name=No Constraint\npolicyset.signingCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.signingCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.signingCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.signingCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.signingCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.signingCertSet.8.constraint.name=No Constraint\npolicyset.signingCertSet.8.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.signingCertSet.8.default.name=Subject Alt Name Constraint\npolicyset.signingCertSet.8.default.params.subjAltNameExtCritical=false\npolicyset.signingCertSet.8.default.params.subjAltExtType_0=RFC822Name\npolicyset.signingCertSet.8.default.params.subjAltExtPattern_0=$request.requestor_email$\npolicyset.signingCertSet.8.default.params.subjAltExtGNEnable_0=true\npolicyset.signingCertSet.8.default.params.subjAltNameNumGNs=1\npolicyset.signingCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.signingCertSet.9.constraint.name=No Constraint\npolicyset.signingCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withEC,SHA512withEC\npolicyset.signingCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.signingCertSet.9.default.name=Signing Alg\npolicyset.signingCertSet.9.default.params.signingAlg=-\npolicyset.signingCertSet.9.default.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withEC,SHA512withEC\nprofileId=caDirBasedDualCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:18Z DEBUG response status 409 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:18Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:18Z DEBUG Error migrating 'caDirBasedDualCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:18Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caDirBasedDualCert?action=enable 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 500 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:17 GMT Connection: close 2019-01-17T11:04:18Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:18Z DEBUG Failed to enable profile 'caDirBasedDualCert' (it is probably already enabled) 2019-01-17T11:04:18Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 204 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=9AC408DC4A9EBE09F38CBD234131EC89; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:18Z DEBUG response body '' 2019-01-17T11:04:18Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 200 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=02E926FC8B92A12C3923B3C9BADA90E5; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:18Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:18Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:18Z DEBUG request body "desc=This certificate profile is for enrolling Administrator's certificates suitable for use by clients such as browsers.\nvisible=true\nenable=true\nenableBy=admin\nauth.instance_id=\nname=Manual Administrator Certificate Enrollment\ninput.list=i1,i2,i3\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\ninput.i3.class_id=subjectDNInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=adminCertSet\npolicyset.adminCertSet.list=1,2,3,4,5,6,7,8\npolicyset.adminCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.adminCertSet.1.constraint.name=Subject Name Constraint\npolicyset.adminCertSet.1.constraint.params.pattern=.*\npolicyset.adminCertSet.1.constraint.params.accept=true\npolicyset.adminCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.adminCertSet.1.default.name=Subject Name Default\npolicyset.adminCertSet.1.default.params.name=\npolicyset.adminCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.adminCertSet.2.constraint.name=Validity Constraint\npolicyset.adminCertSet.2.constraint.params.range=365\npolicyset.adminCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.adminCertSet.2.constraint.params.notAfterCheck=false\npolicyset.adminCertSet.2.default.class_id=validityDefaultImpl\npolicyset.adminCertSet.2.default.name=Validity Default\npolicyset.adminCertSet.2.default.params.range=365\npolicyset.adminCertSet.2.default.params.startTime=0\npolicyset.adminCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.adminCertSet.3.constraint.name=Key Constraint\npolicyset.adminCertSet.3.constraint.params.keyType=RSA\npolicyset.adminCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.adminCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.adminCertSet.3.default.name=Key Default\npolicyset.adminCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.adminCertSet.4.constraint.name=No Constraint\npolicyset.adminCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.adminCertSet.4.default.name=Authority Key Identifier Default\npolicyset.adminCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.adminCertSet.5.constraint.name=No Constraint\npolicyset.adminCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.adminCertSet.5.default.name=AIA Extension Default\npolicyset.adminCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.adminCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.adminCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.adminCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.adminCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.adminCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.adminCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.adminCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.adminCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.adminCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.adminCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.adminCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.adminCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.adminCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.adminCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.adminCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.adminCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.adminCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.adminCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.adminCertSet.6.default.name=Key Usage Default\npolicyset.adminCertSet.6.default.params.keyUsageCritical=true\npolicyset.adminCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.adminCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.adminCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.adminCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.adminCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.adminCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.adminCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.adminCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.adminCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.adminCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.adminCertSet.7.constraint.name=No Constraint\npolicyset.adminCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.adminCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.adminCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.adminCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.adminCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.adminCertSet.8.constraint.name=No Constraint\npolicyset.adminCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.adminCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.adminCertSet.8.default.name=Signing Alg\npolicyset.adminCertSet.8.default.params.signingAlg=-\nprofileId=AdminCert\nclassId=caEnrollImpl\n" 2019-01-17T11:04:18Z DEBUG response status 409 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:18Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:18Z DEBUG Error migrating 'AdminCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:18Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/AdminCert?action=enable 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 500 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:17 GMT Connection: close 2019-01-17T11:04:18Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:18Z DEBUG Failed to enable profile 'AdminCert' (it is probably already enabled) 2019-01-17T11:04:18Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 204 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=2415611D3F25BFCE8B0C1DEC52F8E986; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:18Z DEBUG response body '' 2019-01-17T11:04:18Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 200 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=051A1E08ACB5068487CE7D3AE76BA10A; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:18Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:18Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:18Z DEBUG request body "desc=This certificate profile is for enrolling Administrator's certificates with ECC keys suitable for use by clients such as browsers.\nvisible=true\nenable=true\nenableBy=admin\nauth.instance_id=\nname=Manual Administrator Certificate Enrollment with ECC keys\ninput.list=i1,i2,i3\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\ninput.i3.class_id=subjectDNInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=adminCertSet\npolicyset.adminCertSet.list=1,2,3,4,5,6,7,8\npolicyset.adminCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.adminCertSet.1.constraint.name=Subject Name Constraint\npolicyset.adminCertSet.1.constraint.params.pattern=.*\npolicyset.adminCertSet.1.constraint.params.accept=true\npolicyset.adminCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.adminCertSet.1.default.name=Subject Name Default\npolicyset.adminCertSet.1.default.params.name=\npolicyset.adminCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.adminCertSet.2.constraint.name=Validity Constraint\npolicyset.adminCertSet.2.constraint.params.range=365\npolicyset.adminCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.adminCertSet.2.constraint.params.notAfterCheck=false\npolicyset.adminCertSet.2.default.class_id=validityDefaultImpl\npolicyset.adminCertSet.2.default.name=Validity Default\npolicyset.adminCertSet.2.default.params.range=365\npolicyset.adminCertSet.2.default.params.startTime=0\npolicyset.adminCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.adminCertSet.3.constraint.name=Key Constraint\npolicyset.adminCertSet.3.constraint.params.keyType=-\npolicyset.adminCertSet.3.constraint.params.keyParameters=nistp256,nistp384,nistp521\npolicyset.adminCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.adminCertSet.3.default.name=Key Default\npolicyset.adminCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.adminCertSet.4.constraint.name=No Constraint\npolicyset.adminCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.adminCertSet.4.default.name=Authority Key Identifier Default\npolicyset.adminCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.adminCertSet.5.constraint.name=No Constraint\npolicyset.adminCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.adminCertSet.5.default.name=AIA Extension Default\npolicyset.adminCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.adminCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.adminCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.adminCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.adminCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.adminCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.adminCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.adminCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.adminCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.adminCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.adminCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.adminCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.adminCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.adminCertSet.6.constraint.params.keyUsageKeyAgreement=true\npolicyset.adminCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.adminCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.adminCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.adminCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.adminCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.adminCertSet.6.default.name=Key Usage Default\npolicyset.adminCertSet.6.default.params.keyUsageCritical=true\npolicyset.adminCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.adminCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.adminCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.adminCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.adminCertSet.6.default.params.keyUsageKeyAgreement=true\npolicyset.adminCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.adminCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.adminCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.adminCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.adminCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.adminCertSet.7.constraint.name=No Constraint\npolicyset.adminCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.adminCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.adminCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.adminCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.adminCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.adminCertSet.8.constraint.name=No Constraint\npolicyset.adminCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.adminCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.adminCertSet.8.default.name=Signing Alg\npolicyset.adminCertSet.8.default.params.signingAlg=-\nprofileId=ECAdminCert\nclassId=caEnrollImpl\n" 2019-01-17T11:04:18Z DEBUG response status 409 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:18Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:18Z DEBUG Error migrating 'ECAdminCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:18Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/ECAdminCert?action=enable 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 500 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:17 GMT Connection: close 2019-01-17T11:04:18Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:18Z DEBUG Failed to enable profile 'ECAdminCert' (it is probably already enabled) 2019-01-17T11:04:18Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 204 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=A255C4BD815514B90C8818842D1438B2; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:18Z DEBUG response body '' 2019-01-17T11:04:18Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 200 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=637D9E772EBA2ACC56766CF41E17E4F1; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:18Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:18Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:18Z DEBUG request body 'desc=This profile is for enrolling audit log signing certificates\nvisible=true\nenable=true\nenableBy=admin\nauth.class_id=\nname=Manual Audit Log Signing Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=caLogSigningSet\npolicyset.caLogSigningSet.list=1,2,3,4,6,8,9\npolicyset.caLogSigningSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.caLogSigningSet.1.constraint.name=Subject Name Constraint\npolicyset.caLogSigningSet.1.constraint.params.pattern=CN=.*\npolicyset.caLogSigningSet.1.constraint.params.accept=true\npolicyset.caLogSigningSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.caLogSigningSet.1.default.name=Subject Name Default\npolicyset.caLogSigningSet.1.default.params.name=\npolicyset.caLogSigningSet.2.constraint.class_id=validityConstraintImpl\npolicyset.caLogSigningSet.2.constraint.name=Validity Constraint\npolicyset.caLogSigningSet.2.constraint.params.range=720\npolicyset.caLogSigningSet.2.constraint.params.notBeforeCheck=false\npolicyset.caLogSigningSet.2.constraint.params.notAfterCheck=false\npolicyset.caLogSigningSet.2.default.class_id=validityDefaultImpl\npolicyset.caLogSigningSet.2.default.name=Validity Default\npolicyset.caLogSigningSet.2.default.params.range=720\npolicyset.caLogSigningSet.2.default.params.startTime=0\npolicyset.caLogSigningSet.3.constraint.class_id=keyConstraintImpl\npolicyset.caLogSigningSet.3.constraint.name=Key Constraint\npolicyset.caLogSigningSet.3.constraint.params.keyType=-\npolicyset.caLogSigningSet.3.constraint.params.keyParameters=1024,2048,3072,4096,nistp256,nistp521\npolicyset.caLogSigningSet.3.default.class_id=userKeyDefaultImpl\npolicyset.caLogSigningSet.3.default.name=Key Default\npolicyset.caLogSigningSet.4.constraint.class_id=noConstraintImpl\npolicyset.caLogSigningSet.4.constraint.name=No Constraint\npolicyset.caLogSigningSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.caLogSigningSet.4.default.name=Authority Key Identifier Default\npolicyset.caLogSigningSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.caLogSigningSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.caLogSigningSet.6.constraint.params.keyUsageCritical=true\npolicyset.caLogSigningSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.caLogSigningSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.caLogSigningSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.caLogSigningSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.caLogSigningSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.caLogSigningSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.caLogSigningSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.caLogSigningSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.caLogSigningSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.caLogSigningSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.caLogSigningSet.6.default.name=Key Usage Default\npolicyset.caLogSigningSet.6.default.params.keyUsageCritical=true\npolicyset.caLogSigningSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.caLogSigningSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.caLogSigningSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.caLogSigningSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.caLogSigningSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.caLogSigningSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.caLogSigningSet.6.default.params.keyUsageCrlSign=false\npolicyset.caLogSigningSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.caLogSigningSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.caLogSigningSet.8.constraint.class_id=noConstraintImpl\npolicyset.caLogSigningSet.8.constraint.name=No Constraint\npolicyset.caLogSigningSet.8.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.caLogSigningSet.8.default.name=Subject Key Identifier Extension Default\npolicyset.caLogSigningSet.8.default.params.critical=false\npolicyset.caLogSigningSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.caLogSigningSet.9.constraint.name=No Constraint\npolicyset.caLogSigningSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.caLogSigningSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.caLogSigningSet.9.default.name=Signing Alg\npolicyset.caLogSigningSet.9.default.params.signingAlg=-\nprofileId=caSignedLogCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:18Z DEBUG response status 409 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:18Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:18Z DEBUG Error migrating 'caSignedLogCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:18Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caSignedLogCert?action=enable 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 500 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:17 GMT Connection: close 2019-01-17T11:04:18Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:18Z DEBUG Failed to enable profile 'caSignedLogCert' (it is probably already enabled) 2019-01-17T11:04:18Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 204 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=8C8B557840FB30F9D06DF39002CE7B9A; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:18Z DEBUG response body '' 2019-01-17T11:04:18Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 200 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=0B5C684433DD3DD4565FA13DEBCB40FD; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:18Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:18Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:18Z DEBUG request body 'desc=This certificate profile is for enrolling TPS server certificates.\nvisible=true\nenable=true\nenableBy=admin\nauth.class_id=\nname=Manual TPS Server Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=720\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=720\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=-\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,nistp256,nistp384,nistp521\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\nprofileId=caTPSCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:18Z DEBUG response status 409 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:17 GMT 2019-01-17T11:04:18Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:18Z DEBUG Error migrating 'caTPSCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:18Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caTPSCert?action=enable 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 500 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:17 GMT Connection: close 2019-01-17T11:04:18Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:18Z DEBUG Failed to enable profile 'caTPSCert' (it is probably already enabled) 2019-01-17T11:04:18Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 204 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=3F18FF26851636C7E323389DF19A5CCA; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:18Z DEBUG response body '' 2019-01-17T11:04:18Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 200 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=60C5B8D895491D03C05828BF3205D7B9; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:18Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:18Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:18Z DEBUG request body 'desc=This certificate profile is for enrolling router certificates.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=raCertAuth\nname=RA Agent-Authenticated Router Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=720\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=720\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\nprofileId=caRARouterCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:18Z DEBUG response status 409 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:18Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:18Z DEBUG Error migrating 'caRARouterCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:18Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caRARouterCert?action=enable 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 500 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:18 GMT Connection: close 2019-01-17T11:04:18Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:18Z DEBUG Failed to enable profile 'caRARouterCert' (it is probably already enabled) 2019-01-17T11:04:18Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 204 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=AA24D559F3E52EC232443B12305B581D; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:18Z DEBUG response body '' 2019-01-17T11:04:18Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 200 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=88A07009531C4E05AC3DEBA68FE943F8; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:18Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:18Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:18Z DEBUG request body 'desc=This certificate profile is for enrolling router certificates.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=flatFileAuth\nname=One Time Pin Router Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=720\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=720\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\nprofileId=caRouterCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:18Z DEBUG response status 409 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:18Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:18Z DEBUG Error migrating 'caRouterCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:18Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caRouterCert?action=enable 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 500 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:18 GMT Connection: close 2019-01-17T11:04:18Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:18Z DEBUG Failed to enable profile 'caRouterCert' (it is probably already enabled) 2019-01-17T11:04:18Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 204 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=FE556EE4C93B4E19D45EC95720B619A4; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:18Z DEBUG response body '' 2019-01-17T11:04:18Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 200 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=1BB5AEFB3037C70F81B29D2470B016C3; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:18Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:18Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:18Z DEBUG request body 'desc=This certificate profile is for enrolling server certificates.\nvisible=true\nenable=true\nenableBy=admin\nauth.class_id=\nname=Manual Server Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,12\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=.*CN=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=720\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=720\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.12.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.12.constraint.name=No Constraint\npolicyset.serverCertSet.12.default.class_id=commonNameToSANDefaultImpl\npolicyset.serverCertSet.12.default.name=Copy Common Name to Subject Alternative Name Extension\nprofileId=caServerCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:18Z DEBUG response status 409 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:18Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:18Z DEBUG Error migrating 'caServerCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:18Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caServerCert?action=enable 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 500 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:18 GMT Connection: close 2019-01-17T11:04:18Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:18Z DEBUG Failed to enable profile 'caServerCert' (it is probably already enabled) 2019-01-17T11:04:18Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 204 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=0E0932FE1B58AEA7409F96AD2981EE85; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:18Z DEBUG response body '' 2019-01-17T11:04:18Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 200 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=2A410C0EA80B97373F1EDCEDBA11FD2C; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:18Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:18Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:18Z DEBUG request body 'desc=This certificate profile is for enrolling server certificates with ECC keys.\nvisible=true\nenable=true\nenableBy=admin\nauth.class_id=\nname=Manual Server Certificate Enrollment with ECC keys\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,12\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=.*CN=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=720\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=720\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=-\npolicyset.serverCertSet.3.constraint.params.keyParameters=nistp256,nistp384,nistp521\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.12.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.12.constraint.name=No Constraint\npolicyset.serverCertSet.12.default.class_id=commonNameToSANDefaultImpl\npolicyset.serverCertSet.12.default.name=Copy Common Name to Subject Alternative Name Extension\nprofileId=caECServerCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:18Z DEBUG response status 409 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:18Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:18Z DEBUG Error migrating 'caECServerCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:18Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caECServerCert?action=enable 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 500 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:18 GMT Connection: close 2019-01-17T11:04:18Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:18Z DEBUG Failed to enable profile 'caECServerCert' (it is probably already enabled) 2019-01-17T11:04:18Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 204 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=F8095D42CD32DCD9FE9867D3CE18F71B; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:18Z DEBUG response body '' 2019-01-17T11:04:18Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 200 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=6E0E7334985EF430F3B903DE33C5F2B4; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:18Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:18Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:18Z DEBUG request body 'desc=This certificate profile is for enrolling subsystem certificates.\nvisible=true\nenable=true\nenableBy=admin\nauth.class_id=\nname=Manual Subsystem Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=720\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=720\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\nprofileId=caSubsystemCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:18Z DEBUG response status 409 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:18Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:18Z DEBUG Error migrating 'caSubsystemCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:18Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caSubsystemCert?action=enable 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 500 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:18 GMT Connection: close 2019-01-17T11:04:18Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:18Z DEBUG Failed to enable profile 'caSubsystemCert' (it is probably already enabled) 2019-01-17T11:04:18Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 204 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=6A8D8B6CD5F4606E03DA789CEA453F68; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:18Z DEBUG response body '' 2019-01-17T11:04:18Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 200 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=53966E0E758E8EE6D3241978B382E67A; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:18Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:18Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:18Z DEBUG request body 'desc=This certificate profile is for enrolling subsystem certificates with ECC keys.\nvisible=true\nenable=true\nenableBy=admin\nauth.class_id=\nname=Manual Subsystem Certificate Enrollment with ECC keys\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=720\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=720\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=-\npolicyset.serverCertSet.3.constraint.params.keyParameters=nistp256,nistp384,nistp521\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\nprofileId=caECSubsystemCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:18Z DEBUG response status 409 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:18Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:18Z DEBUG Error migrating 'caECSubsystemCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:18Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caECSubsystemCert?action=enable 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 500 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:18 GMT Connection: close 2019-01-17T11:04:18Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:18Z DEBUG Failed to enable profile 'caECSubsystemCert' (it is probably already enabled) 2019-01-17T11:04:18Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 204 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=1AFA7435E190DD1CA181A899DA86D038; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:18Z DEBUG response body '' 2019-01-17T11:04:18Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 200 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=0AEBE42A8F0E29834BBD88253A4C6A85; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:18Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:18Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:18Z DEBUG request body 'desc=This certificate profile is for enrolling other certificates.\nvisible=true\nenable=true\nenableBy=admin\nauth.class_id=\nname=Other Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=otherCertSet\npolicyset.otherCertSet.list=1,2,3,4,5,6,7,8\npolicyset.otherCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.otherCertSet.1.constraint.name=Subject Name Constraint\npolicyset.otherCertSet.1.constraint.params.pattern=CN=.*\npolicyset.otherCertSet.1.constraint.params.accept=true\npolicyset.otherCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.otherCertSet.1.default.name=Subject Name Default\npolicyset.otherCertSet.1.default.params.name=\npolicyset.otherCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.otherCertSet.2.constraint.name=Validity Constraint\npolicyset.otherCertSet.2.constraint.params.range=720\npolicyset.otherCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.otherCertSet.2.constraint.params.notAfterCheck=false\npolicyset.otherCertSet.2.default.class_id=validityDefaultImpl\npolicyset.otherCertSet.2.default.name=Validity Default\npolicyset.otherCertSet.2.default.params.range=720\npolicyset.otherCertSet.2.default.params.startTime=0\npolicyset.otherCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.otherCertSet.3.constraint.name=Key Constraint\npolicyset.otherCertSet.3.constraint.params.keyType=-\npolicyset.otherCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,nistp256,nistp384,nistp521\npolicyset.otherCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.otherCertSet.3.default.name=Key Default\npolicyset.otherCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.otherCertSet.4.constraint.name=No Constraint\npolicyset.otherCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.otherCertSet.4.default.name=Authority Key Identifier Default\npolicyset.otherCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.otherCertSet.5.constraint.name=No Constraint\npolicyset.otherCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.otherCertSet.5.default.name=AIA Extension Default\npolicyset.otherCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.otherCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.otherCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.otherCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.otherCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.otherCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.otherCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.otherCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.otherCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.otherCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.otherCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.otherCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.otherCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.otherCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.otherCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.otherCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.otherCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.otherCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.otherCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.otherCertSet.6.default.name=Key Usage Default\npolicyset.otherCertSet.6.default.params.keyUsageCritical=true\npolicyset.otherCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.otherCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.otherCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.otherCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.otherCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.otherCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.otherCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.otherCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.otherCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.otherCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.otherCertSet.7.constraint.name=No Constraint\npolicyset.otherCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.otherCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.otherCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.otherCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2\npolicyset.otherCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.otherCertSet.8.constraint.name=No Constraint\npolicyset.otherCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.otherCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.otherCertSet.8.default.name=Signing Alg\npolicyset.otherCertSet.8.default.params.signingAlg=-\nprofileId=caOtherCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:18Z DEBUG response status 409 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:18Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:18Z DEBUG Error migrating 'caOtherCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:18Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caOtherCert?action=enable 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 500 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:18 GMT Connection: close 2019-01-17T11:04:18Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:18Z DEBUG Failed to enable profile 'caOtherCert' (it is probably already enabled) 2019-01-17T11:04:18Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 204 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=175BFEF90968E959F07E762A959F916A; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:18Z DEBUG response body '' 2019-01-17T11:04:18Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:18Z DEBUG request body '' 2019-01-17T11:04:18Z DEBUG response status 200 2019-01-17T11:04:18Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=461B972DE0A7EA95FE2FBB5EB3DA43F7; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:18Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:18Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:18Z DEBUG request body 'desc=This certificate profile is for enrolling Certificate Authority certificates.\nvisible=true\nenable=true\nenableBy=admin\nauth.class_id=\nname=Manual Certificate Manager Signing Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=caCertSet\npolicyset.caCertSet.list=1,2,3,4,5,6,8,9,10\npolicyset.caCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.caCertSet.1.constraint.name=Subject Name Constraint\npolicyset.caCertSet.1.constraint.params.pattern=CN=.*\npolicyset.caCertSet.1.constraint.params.accept=true\npolicyset.caCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.caCertSet.1.default.name=Subject Name Default\npolicyset.caCertSet.1.default.params.name=\npolicyset.caCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.caCertSet.2.constraint.name=Validity Constraint\npolicyset.caCertSet.2.constraint.params.range=7305\npolicyset.caCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.caCertSet.2.constraint.params.notAfterCheck=false\npolicyset.caCertSet.2.default.class_id=caValidityDefaultImpl\npolicyset.caCertSet.2.default.name=CA Certificate Validity Default\npolicyset.caCertSet.2.default.params.range=7305\npolicyset.caCertSet.2.default.params.startTime=0\npolicyset.caCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.caCertSet.3.constraint.name=Key Constraint\npolicyset.caCertSet.3.constraint.params.keyType=-\npolicyset.caCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,nistp256,nistp384,nistp521\npolicyset.caCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.caCertSet.3.default.name=Key Default\npolicyset.caCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.caCertSet.4.constraint.name=No Constraint\npolicyset.caCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.caCertSet.4.default.name=Authority Key Identifier Default\npolicyset.caCertSet.5.constraint.class_id=basicConstraintsExtConstraintImpl\npolicyset.caCertSet.5.constraint.name=Basic Constraint Extension Constraint\npolicyset.caCertSet.5.constraint.params.basicConstraintsCritical=true\npolicyset.caCertSet.5.constraint.params.basicConstraintsIsCA=true\npolicyset.caCertSet.5.constraint.params.basicConstraintsMinPathLen=-1\npolicyset.caCertSet.5.constraint.params.basicConstraintsMaxPathLen=-1\npolicyset.caCertSet.5.default.class_id=basicConstraintsExtDefaultImpl\npolicyset.caCertSet.5.default.name=Basic Constraints Extension Default\npolicyset.caCertSet.5.default.params.basicConstraintsCritical=true\npolicyset.caCertSet.5.default.params.basicConstraintsIsCA=true\npolicyset.caCertSet.5.default.params.basicConstraintsPathLen=-1\npolicyset.caCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.caCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.caCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.caCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.caCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.caCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.caCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.caCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.caCertSet.6.constraint.params.keyUsageKeyCertSign=true\npolicyset.caCertSet.6.constraint.params.keyUsageCrlSign=true\npolicyset.caCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.caCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.caCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.caCertSet.6.default.name=Key Usage Default\npolicyset.caCertSet.6.default.params.keyUsageCritical=true\npolicyset.caCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.caCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.caCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.caCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.caCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.caCertSet.6.default.params.keyUsageKeyCertSign=true\npolicyset.caCertSet.6.default.params.keyUsageCrlSign=true\npolicyset.caCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.caCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.caCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.caCertSet.8.constraint.name=No Constraint\npolicyset.caCertSet.8.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.caCertSet.8.default.name=Subject Key Identifier Extension Default\npolicyset.caCertSet.8.default.params.critical=false\npolicyset.caCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.caCertSet.9.constraint.name=No Constraint\npolicyset.caCertSet.9.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.caCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.caCertSet.9.default.name=Signing Alg\npolicyset.caCertSet.9.default.params.signingAlg=-\npolicyset.caCertSet.10.constraint.class_id=noConstraintImpl\npolicyset.caCertSet.10.constraint.name=No Constraint\npolicyset.caCertSet.10.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.caCertSet.10.default.name=AIA Extension Default\npolicyset.caCertSet.10.default.params.authInfoAccessADEnable_0=true\npolicyset.caCertSet.10.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.caCertSet.10.default.params.authInfoAccessADLocation_0=\npolicyset.caCertSet.10.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.caCertSet.10.default.params.authInfoAccessCritical=false\npolicyset.caCertSet.10.default.params.authInfoAccessNumADs=1\nprofileId=caCACert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:19Z DEBUG response status 409 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:19Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:19Z DEBUG Error migrating 'caCACert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:19Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caCACert?action=enable 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 500 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:18 GMT Connection: close 2019-01-17T11:04:19Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:19Z DEBUG Failed to enable profile 'caCACert' (it is probably already enabled) 2019-01-17T11:04:19Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 204 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=34B3061E870300BD5A0AA898B9E61C62; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:19Z DEBUG response body '' 2019-01-17T11:04:19Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 200 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=F59D62B01F9531B062F27E60CF9043B6; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:19Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:19Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:19Z DEBUG request body 'desc=This certificate profile is for enrolling Certificate Authority certificates using CMC.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=CMCAuth\nauthz.acl=group="Certificate Manager Agents"\nname=Certificate Manager Signing Certificate Enrollment using CMC\ninput.list=i1\ninput.i1.class_id=cmcCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=caCertSet\npolicyset.caCertSet.list=1,2,3,4,5,6,8,9,10\npolicyset.caCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.caCertSet.1.constraint.name=Subject Name Constraint\npolicyset.caCertSet.1.constraint.params.pattern=CN=.*\npolicyset.caCertSet.1.constraint.params.accept=true\npolicyset.caCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.caCertSet.1.default.name=Subject Name Default\npolicyset.caCertSet.1.default.params.name=\npolicyset.caCertSet.2.constraint.class_id=caValidityConstraintImpl\npolicyset.caCertSet.2.constraint.name=CA Validity Constraint\npolicyset.caCertSet.2.constraint.params.range=7305\npolicyset.caCertSet.2.default.class_id=caValidityDefaultImpl\npolicyset.caCertSet.2.default.name=CA Certificate Validity Default\npolicyset.caCertSet.2.default.params.range=7305\npolicyset.caCertSet.2.default.params.startTime=0\npolicyset.caCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.caCertSet.3.constraint.name=Key Constraint\npolicyset.caCertSet.3.constraint.params.keyType=-\npolicyset.caCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,nistp256,nistp384,nistp521\npolicyset.caCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.caCertSet.3.default.name=Key Default\npolicyset.caCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.caCertSet.4.constraint.name=No Constraint\npolicyset.caCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.caCertSet.4.default.name=Authority Key Identifier Default\npolicyset.caCertSet.5.constraint.class_id=basicConstraintsExtConstraintImpl\npolicyset.caCertSet.5.constraint.name=Basic Constraint Extension Constraint\npolicyset.caCertSet.5.constraint.params.basicConstraintsCritical=true\npolicyset.caCertSet.5.constraint.params.basicConstraintsIsCA=true\npolicyset.caCertSet.5.constraint.params.basicConstraintsMinPathLen=-1\npolicyset.caCertSet.5.constraint.params.basicConstraintsMaxPathLen=-1\npolicyset.caCertSet.5.default.class_id=basicConstraintsExtDefaultImpl\npolicyset.caCertSet.5.default.name=Basic Constraints Extension Default\npolicyset.caCertSet.5.default.params.basicConstraintsCritical=true\npolicyset.caCertSet.5.default.params.basicConstraintsIsCA=true\npolicyset.caCertSet.5.default.params.basicConstraintsPathLen=-1\npolicyset.caCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.caCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.caCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.caCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.caCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.caCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.caCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.caCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.caCertSet.6.constraint.params.keyUsageKeyCertSign=true\npolicyset.caCertSet.6.constraint.params.keyUsageCrlSign=true\npolicyset.caCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.caCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.caCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.caCertSet.6.default.name=Key Usage Default\npolicyset.caCertSet.6.default.params.keyUsageCritical=true\npolicyset.caCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.caCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.caCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.caCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.caCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.caCertSet.6.default.params.keyUsageKeyCertSign=true\npolicyset.caCertSet.6.default.params.keyUsageCrlSign=true\npolicyset.caCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.caCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.caCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.caCertSet.8.constraint.name=No Constraint\npolicyset.caCertSet.8.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.caCertSet.8.default.name=Subject Key Identifier Extension Default\npolicyset.caCertSet.8.default.params.critical=false\npolicyset.caCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.caCertSet.9.constraint.name=No Constraint\npolicyset.caCertSet.9.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.caCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.caCertSet.9.default.name=Signing Alg\npolicyset.caCertSet.9.default.params.signingAlg=-\npolicyset.caCertSet.10.constraint.class_id=noConstraintImpl\npolicyset.caCertSet.10.constraint.name=No Constraint\npolicyset.caCertSet.10.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.caCertSet.10.default.name=AIA Extension Default\npolicyset.caCertSet.10.default.params.authInfoAccessADEnable_0=true\npolicyset.caCertSet.10.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.caCertSet.10.default.params.authInfoAccessADLocation_0=\npolicyset.caCertSet.10.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.caCertSet.10.default.params.authInfoAccessCritical=false\npolicyset.caCertSet.10.default.params.authInfoAccessNumADs=1\nprofileId=caCMCcaCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:19Z DEBUG response status 409 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:19Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:19Z DEBUG Error migrating 'caCMCcaCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:19Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caCMCcaCert?action=enable 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 500 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:18 GMT Connection: close 2019-01-17T11:04:19Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:19Z DEBUG Failed to enable profile 'caCMCcaCert' (it is probably already enabled) 2019-01-17T11:04:19Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 204 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=0C7EED6F994E5AF915CC24D577130822; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:19Z DEBUG response body '' 2019-01-17T11:04:19Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 200 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=547218A1A139A39C969A04D39D48D008; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:19Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:19Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:19Z DEBUG request body 'desc=This certificate profile is for enrolling Cross Signed Certificate Authority certificates.\nvisible=false\nenable=false\nenableBy=admin\nauth.class_id=\nname=Manual Cross Signed Certificate Manager Signing Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=caCertSet\npolicyset.caCertSet.list=1,2,3,4,5,6,8,9,10\npolicyset.caCertSet.1.constraint.class_id=userSubjectNameConstraintImpl\npolicyset.caCertSet.1.constraint.name=User Subject Name Constraint\npolicyset.caCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.caCertSet.1.default.name=User Supplied Subject Name Default\npolicyset.caCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.caCertSet.2.constraint.name=Validity Constraint\npolicyset.caCertSet.2.constraint.params.range=7305\npolicyset.caCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.caCertSet.2.constraint.params.notAfterCheck=false\npolicyset.caCertSet.2.default.class_id=caValidityDefaultImpl\npolicyset.caCertSet.2.default.name=CA Certificate Validity Default\npolicyset.caCertSet.2.default.params.range=7305\npolicyset.caCertSet.2.default.params.startTime=0\npolicyset.caCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.caCertSet.3.constraint.name=Key Constraint\npolicyset.caCertSet.3.constraint.params.keyType=-\npolicyset.caCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,nistp256,nistp384,nistp521\npolicyset.caCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.caCertSet.3.default.name=Key Default\npolicyset.caCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.caCertSet.4.constraint.name=No Constraint\npolicyset.caCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.caCertSet.4.default.name=Authority Key Identifier Default\npolicyset.caCertSet.5.constraint.class_id=basicConstraintsExtConstraintImpl\npolicyset.caCertSet.5.constraint.name=Basic Constraint Extension Constraint\npolicyset.caCertSet.5.constraint.params.basicConstraintsCritical=true\npolicyset.caCertSet.5.constraint.params.basicConstraintsIsCA=true\npolicyset.caCertSet.5.constraint.params.basicConstraintsMinPathLen=-1\npolicyset.caCertSet.5.constraint.params.basicConstraintsMaxPathLen=-1\npolicyset.caCertSet.5.default.class_id=basicConstraintsExtDefaultImpl\npolicyset.caCertSet.5.default.name=Basic Constraints Extension Default\npolicyset.caCertSet.5.default.params.basicConstraintsCritical=true\npolicyset.caCertSet.5.default.params.basicConstraintsIsCA=true\npolicyset.caCertSet.5.default.params.basicConstraintsPathLen=-1\npolicyset.caCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.caCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.caCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.caCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.caCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.caCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.caCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.caCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.caCertSet.6.constraint.params.keyUsageKeyCertSign=true\npolicyset.caCertSet.6.constraint.params.keyUsageCrlSign=true\npolicyset.caCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.caCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.caCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.caCertSet.6.default.name=Key Usage Default\npolicyset.caCertSet.6.default.params.keyUsageCritical=true\npolicyset.caCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.caCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.caCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.caCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.caCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.caCertSet.6.default.params.keyUsageKeyCertSign=true\npolicyset.caCertSet.6.default.params.keyUsageCrlSign=true\npolicyset.caCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.caCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.caCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.caCertSet.8.constraint.name=No Constraint\npolicyset.caCertSet.8.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.caCertSet.8.default.name=Subject Key Identifier Extension Default\npolicyset.caCertSet.8.default.params.critical=false\npolicyset.caCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.caCertSet.9.constraint.name=No Constraint\npolicyset.caCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.caCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.caCertSet.9.default.name=Signing Alg\npolicyset.caCertSet.9.default.params.signingAlg=-\npolicyset.caCertSet.10.constraint.class_id=noConstraintImpl\npolicyset.caCertSet.10.constraint.name=No Constraint\npolicyset.caCertSet.10.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.caCertSet.10.default.name=AIA Extension Default\npolicyset.caCertSet.10.default.params.authInfoAccessADEnable_0=true\npolicyset.caCertSet.10.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.caCertSet.10.default.params.authInfoAccessADLocation_0=\npolicyset.caCertSet.10.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.caCertSet.10.default.params.authInfoAccessCritical=false\npolicyset.caCertSet.10.default.params.authInfoAccessNumADs=1\nprofileId=caCrossSignedCACert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:19Z DEBUG response status 409 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:19Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:19Z DEBUG Error migrating 'caCrossSignedCACert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:19Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caCrossSignedCACert?action=enable 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 500 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:18 GMT Connection: close 2019-01-17T11:04:19Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:19Z DEBUG Failed to enable profile 'caCrossSignedCACert' (it is probably already enabled) 2019-01-17T11:04:19Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 204 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=DA033C5E8C15F2FB31244A8C41ECE17D; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:19Z DEBUG response body '' 2019-01-17T11:04:19Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 200 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=DB76E6AAEB296EB5FC62A01367B7E8B0; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:19Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:19Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:19Z DEBUG request body 'desc=This certificate profile is for enrolling Security Domain Certificate Authority certificates.\nvisible=true\nenable=true\nenableBy=admin\nauth.instance_id=TokenAuth\nauthz.acl=group="Enterprise OCSP Administrators" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators"\nname=Manual Security Domain Certificate Authority Signing Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=caCertSet\npolicyset.caCertSet.list=1,2,3,4,5,6,8,9,10\npolicyset.caCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.caCertSet.1.constraint.name=Subject Name Constraint\npolicyset.caCertSet.1.constraint.params.pattern=CN=.*\npolicyset.caCertSet.1.constraint.params.accept=true\npolicyset.caCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.caCertSet.1.default.name=Subject Name Default\npolicyset.caCertSet.1.default.params.name=\npolicyset.caCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.caCertSet.2.constraint.name=Validity Constraint\npolicyset.caCertSet.2.constraint.params.range=720\npolicyset.caCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.caCertSet.2.constraint.params.notAfterCheck=false\npolicyset.caCertSet.2.default.class_id=validityDefaultImpl\npolicyset.caCertSet.2.default.name=Validity Default\npolicyset.caCertSet.2.default.params.range=720\npolicyset.caCertSet.2.default.params.startTime=0\npolicyset.caCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.caCertSet.3.constraint.name=Key Constraint\npolicyset.caCertSet.3.constraint.params.keyType=-\npolicyset.caCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,nistp256,nistp384,nistp521\npolicyset.caCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.caCertSet.3.default.name=Key Default\npolicyset.caCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.caCertSet.4.constraint.name=No Constraint\npolicyset.caCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.caCertSet.4.default.name=Authority Key Identifier Default\npolicyset.caCertSet.5.constraint.class_id=basicConstraintsExtConstraintImpl\npolicyset.caCertSet.5.constraint.name=Basic Constraint Extension Constraint\npolicyset.caCertSet.5.constraint.params.basicConstraintsCritical=true\npolicyset.caCertSet.5.constraint.params.basicConstraintsIsCA=true\npolicyset.caCertSet.5.constraint.params.basicConstraintsMinPathLen=-1\npolicyset.caCertSet.5.constraint.params.basicConstraintsMaxPathLen=-1\npolicyset.caCertSet.5.default.class_id=basicConstraintsExtDefaultImpl\npolicyset.caCertSet.5.default.name=Basic Constraints Extension Default\npolicyset.caCertSet.5.default.params.basicConstraintsCritical=true\npolicyset.caCertSet.5.default.params.basicConstraintsIsCA=true\npolicyset.caCertSet.5.default.params.basicConstraintsPathLen=-1\npolicyset.caCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.caCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.caCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.caCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.caCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.caCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.caCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.caCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.caCertSet.6.constraint.params.keyUsageKeyCertSign=true\npolicyset.caCertSet.6.constraint.params.keyUsageCrlSign=true\npolicyset.caCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.caCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.caCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.caCertSet.6.default.name=Key Usage Default\npolicyset.caCertSet.6.default.params.keyUsageCritical=true\npolicyset.caCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.caCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.caCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.caCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.caCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.caCertSet.6.default.params.keyUsageKeyCertSign=true\npolicyset.caCertSet.6.default.params.keyUsageCrlSign=true\npolicyset.caCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.caCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.caCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.caCertSet.8.constraint.name=No Constraint\npolicyset.caCertSet.8.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.caCertSet.8.default.name=Subject Key Identifier Extension Default\npolicyset.caCertSet.8.default.params.critical=false\npolicyset.caCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.caCertSet.9.constraint.name=No Constraint\npolicyset.caCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.caCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.caCertSet.9.default.name=Signing Alg\npolicyset.caCertSet.9.default.params.signingAlg=-\npolicyset.caCertSet.10.constraint.class_id=noConstraintImpl\npolicyset.caCertSet.10.constraint.name=No Constraint\npolicyset.caCertSet.10.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.caCertSet.10.default.name=AIA Extension Default\npolicyset.caCertSet.10.default.params.authInfoAccessADEnable_0=true\npolicyset.caCertSet.10.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.caCertSet.10.default.params.authInfoAccessADLocation_0=\npolicyset.caCertSet.10.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.caCertSet.10.default.params.authInfoAccessCritical=false\npolicyset.caCertSet.10.default.params.authInfoAccessNumADs=1\nprofileId=caInstallCACert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:19Z DEBUG response status 409 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:19Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:19Z DEBUG Error migrating 'caInstallCACert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:19Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caInstallCACert?action=enable 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 500 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:18 GMT Connection: close 2019-01-17T11:04:19Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:19Z DEBUG Failed to enable profile 'caInstallCACert' (it is probably already enabled) 2019-01-17T11:04:19Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 204 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=FA5A518C34CFC8C829756DF08906B5B0; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:19Z DEBUG response body '' 2019-01-17T11:04:19Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 200 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=AA36F4057E875B20E977A62D5819610F; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:19Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:19Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:19Z DEBUG request body 'desc=This certificate profile is for enrolling Registration Manager certificates.\nvisible=false\nenable=false\nenableBy=admin\nauth.class_id=\nname=Manual Registration Manager Signing Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=raCertSet\npolicyset.raCertSet.list=1,2,3,4,5,6,7,8\npolicyset.raCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.raCertSet.1.constraint.name=Subject Name Constraint\npolicyset.raCertSet.1.constraint.params.pattern=CN=.*\npolicyset.raCertSet.1.constraint.params.accept=true\npolicyset.raCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.raCertSet.1.default.name=Subject Name Default\npolicyset.raCertSet.1.default.params.name=\npolicyset.raCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.raCertSet.2.constraint.name=Validity Constraint\npolicyset.raCertSet.2.constraint.params.range=720\npolicyset.raCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.raCertSet.2.constraint.params.notAfterCheck=false\npolicyset.raCertSet.2.default.class_id=validityDefaultImpl\npolicyset.raCertSet.2.default.name=Validity Default\npolicyset.raCertSet.2.default.params.range=720\npolicyset.raCertSet.2.default.params.startTime=0\npolicyset.raCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.raCertSet.3.constraint.name=Key Constraint\npolicyset.raCertSet.3.constraint.params.keyType=RSA\npolicyset.raCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.raCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.raCertSet.3.default.name=Key Default\npolicyset.raCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.raCertSet.4.constraint.name=No Constraint\npolicyset.raCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.raCertSet.4.default.name=Authority Key Identifier Default\npolicyset.raCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.raCertSet.5.constraint.name=No Constraint\npolicyset.raCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.raCertSet.5.default.name=AIA Extension Default\npolicyset.raCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.raCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.raCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.raCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.raCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.raCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.raCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.raCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.raCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.raCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.raCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.raCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.raCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.raCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.raCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.raCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.raCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.raCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.raCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.raCertSet.6.default.name=Key Usage Default\npolicyset.raCertSet.6.default.params.keyUsageCritical=true\npolicyset.raCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.raCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.raCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.raCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.raCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.raCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.raCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.raCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.raCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.raCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.raCertSet.7.constraint.name=No Constraint\npolicyset.raCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.raCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.raCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.raCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2\npolicyset.raCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.raCertSet.8.constraint.name=No Constraint\npolicyset.raCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.raCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.raCertSet.8.default.name=Signing Alg\npolicyset.raCertSet.8.default.params.signingAlg=-\nprofileId=caRACert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:19Z DEBUG response status 409 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:19Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:19Z DEBUG Error migrating 'caRACert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:19Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caRACert?action=enable 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 500 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:18 GMT Connection: close 2019-01-17T11:04:19Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:19Z DEBUG Failed to enable profile 'caRACert' (it is probably already enabled) 2019-01-17T11:04:19Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 204 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=B4537860E8D25DE14EFB3AEE2C0B760B; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:19Z DEBUG response body '' 2019-01-17T11:04:19Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 200 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=278D1D695E49288519828C63FA883C32; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:19Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:19Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:19Z DEBUG request body 'desc=This certificate profile is for enrolling OCSP Manager certificates.\nvisible=true\nenable=true\nenableBy=admin\nauth.class_id=\nname=Manual OCSP Manager Signing Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=ocspCertSet\npolicyset.ocspCertSet.list=1,2,3,4,5,6,8,9\npolicyset.ocspCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.ocspCertSet.1.constraint.name=Subject Name Constraint\npolicyset.ocspCertSet.1.constraint.params.pattern=CN=.*\npolicyset.ocspCertSet.1.constraint.params.accept=true\npolicyset.ocspCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.ocspCertSet.1.default.name=Subject Name Default\npolicyset.ocspCertSet.1.default.params.name=\npolicyset.ocspCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.ocspCertSet.2.constraint.name=Validity Constraint\npolicyset.ocspCertSet.2.constraint.params.range=720\npolicyset.ocspCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.ocspCertSet.2.constraint.params.notAfterCheck=false\npolicyset.ocspCertSet.2.default.class_id=validityDefaultImpl\npolicyset.ocspCertSet.2.default.name=Validity Default\npolicyset.ocspCertSet.2.default.params.range=720\npolicyset.ocspCertSet.2.default.params.startTime=0\npolicyset.ocspCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.ocspCertSet.3.constraint.name=Key Constraint\npolicyset.ocspCertSet.3.constraint.params.keyType=-\npolicyset.ocspCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,nistp256,nistp384,nistp521\npolicyset.ocspCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.ocspCertSet.3.default.name=Key Default\npolicyset.ocspCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.ocspCertSet.4.constraint.name=No Constraint\npolicyset.ocspCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.ocspCertSet.4.default.name=Authority Key Identifier Default\npolicyset.ocspCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.ocspCertSet.5.constraint.name=No Constraint\npolicyset.ocspCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.ocspCertSet.5.default.name=AIA Extension Default\npolicyset.ocspCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.ocspCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.ocspCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.ocspCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.ocspCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.ocspCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.ocspCertSet.6.constraint.class_id=extendedKeyUsageExtConstraintImpl\npolicyset.ocspCertSet.6.constraint.name=Extended Key Usage Extension\npolicyset.ocspCertSet.6.constraint.params.exKeyUsageCritical=false\npolicyset.ocspCertSet.6.constraint.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.9\npolicyset.ocspCertSet.6.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.ocspCertSet.6.default.name=Extended Key Usage Default\npolicyset.ocspCertSet.6.default.params.exKeyUsageCritical=false\npolicyset.ocspCertSet.6.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.9\npolicyset.ocspCertSet.8.constraint.class_id=extensionConstraintImpl\npolicyset.ocspCertSet.8.constraint.name=No Constraint\npolicyset.ocspCertSet.8.constraint.params.extCritical=false\npolicyset.ocspCertSet.8.constraint.params.extOID=1.3.6.1.5.5.7.48.1.5\npolicyset.ocspCertSet.8.default.class_id=ocspNoCheckExtDefaultImpl\npolicyset.ocspCertSet.8.default.name=OCSP No Check Extension\npolicyset.ocspCertSet.8.default.params.ocspNoCheckCritical=false\npolicyset.ocspCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.ocspCertSet.9.constraint.name=No Constraint\npolicyset.ocspCertSet.9.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.ocspCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.ocspCertSet.9.default.name=Signing Alg\npolicyset.ocspCertSet.9.default.params.signingAlg=-\nprofileId=caOCSPCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:19Z DEBUG response status 409 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:19Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:19Z DEBUG Error migrating 'caOCSPCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:19Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caOCSPCert?action=enable 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 500 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:18 GMT Connection: close 2019-01-17T11:04:19Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:19Z DEBUG Failed to enable profile 'caOCSPCert' (it is probably already enabled) 2019-01-17T11:04:19Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 204 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=EF121719CAB6461B33721567762BDA24; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:19Z DEBUG response body '' 2019-01-17T11:04:19Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 200 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=0463AEAB0749BCC788FA4333BB9C971C; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:19Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:19Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:19Z DEBUG request body 'desc=This certificate profile is for enrolling Data Recovery Manager storage certificates.\nvisible=true\nenable=true\nenableBy=admin\nauth.class.id=\nname=Manual Data Recovery Manager Storage Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=drmStorageCertSet\npolicyset.drmStorageCertSet.list=1,2,3,4,5,6,7,9\npolicyset.drmStorageCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.drmStorageCertSet.1.constraint.name=Subject Name Constraint\npolicyset.drmStorageCertSet.1.constraint.params.pattern=CN=.*\npolicyset.drmStorageCertSet.1.constraint.params.accept=true\npolicyset.drmStorageCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.drmStorageCertSet.1.default.name=Subject Name Default\npolicyset.drmStorageCertSet.1.default.params.name=\npolicyset.drmStorageCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.drmStorageCertSet.2.constraint.name=Validity Constraint\npolicyset.drmStorageCertSet.2.constraint.params.range=720\npolicyset.drmStorageCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.drmStorageCertSet.2.constraint.params.notAfterCheck=false\npolicyset.drmStorageCertSet.2.default.class_id=validityDefaultImpl\npolicyset.drmStorageCertSet.2.default.name=Validity Default\npolicyset.drmStorageCertSet.2.default.params.range=720\npolicyset.drmStorageCertSet.2.default.params.startTime=0\npolicyset.drmStorageCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.drmStorageCertSet.3.constraint.name=Key Constraint\npolicyset.drmStorageCertSet.3.constraint.params.keyType=RSA\npolicyset.drmStorageCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.drmStorageCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.drmStorageCertSet.3.default.name=Key Default\npolicyset.drmStorageCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.drmStorageCertSet.4.constraint.name=No Constraint\npolicyset.drmStorageCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.drmStorageCertSet.4.default.name=Authority Key Identifier Default\npolicyset.drmStorageCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.drmStorageCertSet.5.constraint.name=No Constraint\npolicyset.drmStorageCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.drmStorageCertSet.5.default.name=AIA Extension Default\npolicyset.drmStorageCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.drmStorageCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.drmStorageCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.drmStorageCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.drmStorageCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.drmStorageCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.drmStorageCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.drmStorageCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.drmStorageCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.drmStorageCertSet.6.default.name=Key Usage Default\npolicyset.drmStorageCertSet.6.default.params.keyUsageCritical=true\npolicyset.drmStorageCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.drmStorageCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.drmStorageCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.drmStorageCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.drmStorageCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.drmStorageCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.drmStorageCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.drmStorageCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.drmStorageCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.drmStorageCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.drmStorageCertSet.7.constraint.name=No Constraint\npolicyset.drmStorageCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.drmStorageCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.drmStorageCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.drmStorageCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2\npolicyset.drmStorageCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.drmStorageCertSet.9.constraint.name=No Constraint\npolicyset.drmStorageCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.drmStorageCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.drmStorageCertSet.9.default.name=Signing Alg\npolicyset.drmStorageCertSet.9.default.params.signingAlg=-\nprofileId=caStorageCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:19Z DEBUG response status 409 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:19Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:19Z DEBUG Error migrating 'caStorageCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:19Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caStorageCert?action=enable 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 500 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:18 GMT Connection: close 2019-01-17T11:04:19Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:19Z DEBUG Failed to enable profile 'caStorageCert' (it is probably already enabled) 2019-01-17T11:04:19Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 204 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=C93F76B714078FCB4AC4CED095B93506; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:18 GMT 2019-01-17T11:04:19Z DEBUG response body '' 2019-01-17T11:04:19Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 200 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=DB81716E47CE290B872DCB091B2DA9E0; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:19Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:19Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:19Z DEBUG request body 'desc=This certificate profile is for enrolling Data Recovery Manager transport certificates.\nvisible=true\nenable=true\nenableBy=admin\nauth.class_id=\nname=Manual Data Recovery Manager Transport Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=transportCertSet\npolicyset.transportCertSet.list=1,2,3,4,5,6,7,8\npolicyset.transportCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.transportCertSet.1.constraint.name=Subject Name Constraint\npolicyset.transportCertSet.1.constraint.params.pattern=CN=.*\npolicyset.transportCertSet.1.constraint.params.accept=true\npolicyset.transportCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.transportCertSet.1.default.name=Subject Name Default\npolicyset.transportCertSet.1.default.params.name=\npolicyset.transportCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.transportCertSet.2.constraint.name=Validity Constraint\npolicyset.transportCertSet.2.constraint.params.range=720\npolicyset.transportCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.transportCertSet.2.constraint.params.notAfterCheck=false\npolicyset.transportCertSet.2.default.class_id=validityDefaultImpl\npolicyset.transportCertSet.2.default.name=Validity Default\npolicyset.transportCertSet.2.default.params.range=720\npolicyset.transportCertSet.2.default.params.startTime=0\npolicyset.transportCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.transportCertSet.3.constraint.name=Key Constraint\npolicyset.transportCertSet.3.constraint.params.keyType=RSA\npolicyset.transportCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.transportCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.transportCertSet.3.default.name=Key Default\npolicyset.transportCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.transportCertSet.4.constraint.name=No Constraint\npolicyset.transportCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.transportCertSet.4.default.name=Authority Key Identifier Default\npolicyset.transportCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.transportCertSet.5.constraint.name=No Constraint\npolicyset.transportCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.transportCertSet.5.default.name=AIA Extension Default\npolicyset.transportCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.transportCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.transportCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.transportCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.transportCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.transportCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.transportCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.transportCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.transportCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.transportCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.transportCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.transportCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.transportCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.transportCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.transportCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.transportCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.transportCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.transportCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.transportCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.transportCertSet.6.default.name=Key Usage Default\npolicyset.transportCertSet.6.default.params.keyUsageCritical=true\npolicyset.transportCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.transportCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.transportCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.transportCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.transportCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.transportCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.transportCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.transportCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.transportCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.transportCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.transportCertSet.7.constraint.name=No Constraint\npolicyset.transportCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.transportCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.transportCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.transportCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2\npolicyset.transportCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.transportCertSet.8.constraint.name=No Constraint\npolicyset.transportCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.transportCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.transportCertSet.8.default.name=Signing Alg\npolicyset.transportCertSet.8.default.params.signingAlg=-\nprofileId=caTransportCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:19Z DEBUG response status 409 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:19Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:19Z DEBUG Error migrating 'caTransportCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:19Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caTransportCert?action=enable 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 500 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:19 GMT Connection: close 2019-01-17T11:04:19Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:19Z DEBUG Failed to enable profile 'caTransportCert' (it is probably already enabled) 2019-01-17T11:04:19Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 204 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=F1DE86E15FF38D542AEACBA635BB2377; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:19Z DEBUG response body '' 2019-01-17T11:04:19Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 200 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=E3CB5818B49088C04D5425432818B90B; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:19Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:19Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:19Z DEBUG request body 'desc=This certificate profile is for enrolling user certificates with directory-pin-based authentication.\nvisible=true\nenable=false\nenableBy=admin\nname=Directory-Pin-Authenticated User Dual-Use Certificate Enrollment\nauth.instance_id=PinDirEnrollment\ninput.list=i1\ninput.i1.class_id=keyGenInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=userCertSet\npolicyset.userCertSet.list=1,10,2,3,4,5,6,7,8,9\npolicyset.userCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.userCertSet.1.constraint.name=Subject Name Constraint\npolicyset.userCertSet.1.constraint.params.pattern=(UID|CN)=.*\npolicyset.userCertSet.1.constraint.params.accept=true\npolicyset.userCertSet.1.default.class_id=authTokenSubjectNameDefaultImpl\npolicyset.userCertSet.1.default.name=Subject Name Default\npolicyset.userCertSet.1.default.params.name=\npolicyset.userCertSet.10.constraint.class_id=renewGracePeriodConstraintImpl\npolicyset.userCertSet.10.constraint.name=Renewal Grace Period Constraint\npolicyset.userCertSet.10.constraint.params.renewal.graceBefore=30\npolicyset.userCertSet.10.constraint.params.renewal.graceAfter=30\npolicyset.userCertSet.10.default.class_id=noDefaultImpl\npolicyset.userCertSet.10.default.name=No Default\npolicyset.userCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.userCertSet.2.constraint.name=Validity Constraint\npolicyset.userCertSet.2.constraint.params.range=365\npolicyset.userCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.userCertSet.2.constraint.params.notAfterCheck=false\npolicyset.userCertSet.2.default.class_id=validityDefaultImpl\npolicyset.userCertSet.2.default.name=Validity Default\npolicyset.userCertSet.2.default.params.range=180\npolicyset.userCertSet.2.default.params.startTime=0\npolicyset.userCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.userCertSet.3.constraint.name=Key Constraint\npolicyset.userCertSet.3.constraint.params.keyType=RSA\npolicyset.userCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.userCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.userCertSet.3.default.name=Key Default\npolicyset.userCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.4.constraint.name=No Constraint\npolicyset.userCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.userCertSet.4.default.name=Authority Key Identifier Default\npolicyset.userCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.5.constraint.name=No Constraint\npolicyset.userCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.userCertSet.5.default.name=AIA Extension Default\npolicyset.userCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.userCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.userCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.userCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.userCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.userCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.userCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.userCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.userCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.userCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.userCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.userCertSet.6.default.name=Key Usage Default\npolicyset.userCertSet.6.default.params.keyUsageCritical=true\npolicyset.userCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.userCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.userCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.userCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.7.constraint.name=No Constraint\npolicyset.userCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.userCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.userCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.userCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.userCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.8.constraint.name=No Constraint\npolicyset.userCertSet.8.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.userCertSet.8.default.name=Subject Alt Name Constraint\npolicyset.userCertSet.8.default.params.subjAltNameExtCritical=false\npolicyset.userCertSet.8.default.params.subjAltExtType_0=RFC822Name\npolicyset.userCertSet.8.default.params.subjAltExtPattern_0=$request.requestor_email$\npolicyset.userCertSet.8.default.params.subjAltExtGNEnable_0=true\npolicyset.userCertSet.8.default.params.subjAltNameNumGNs=1\npolicyset.userCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.userCertSet.9.constraint.name=No Constraint\npolicyset.userCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.userCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.userCertSet.9.default.name=Signing Alg\npolicyset.userCertSet.9.default.params.signingAlg=-\nprofileId=caDirPinUserCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:19Z DEBUG response status 409 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:19Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:19Z DEBUG Error migrating 'caDirPinUserCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:19Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caDirPinUserCert?action=enable 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 500 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:19 GMT Connection: close 2019-01-17T11:04:19Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:19Z DEBUG Failed to enable profile 'caDirPinUserCert' (it is probably already enabled) 2019-01-17T11:04:19Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 204 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=79C23BABE5CA39B8D5312AE4B30F27E9; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:19Z DEBUG response body '' 2019-01-17T11:04:19Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 200 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=DD18984C40D5D1724101AABE79DD7B26; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:19Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:19Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:19Z DEBUG request body 'desc=This certificate profile is for enrolling user ECC certificates with directory-pin-based authentication.\nvisible=true\nenable=false\nenableBy=admin\nname=Directory-Pin-Authenticated User Dual-Use ECC Certificate Enrollment\nauth.instance_id=PinDirEnrollment\ninput.list=i1\ninput.i1.class_id=keyGenInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=userCertSet\npolicyset.userCertSet.list=1,10,2,3,4,5,6,7,8,9\npolicyset.userCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.userCertSet.1.constraint.name=Subject Name Constraint\npolicyset.userCertSet.1.constraint.params.pattern=(UID|CN)=.*\npolicyset.userCertSet.1.constraint.params.accept=true\npolicyset.userCertSet.1.default.class_id=authTokenSubjectNameDefaultImpl\npolicyset.userCertSet.1.default.name=Subject Name Default\npolicyset.userCertSet.1.default.params.name=\npolicyset.userCertSet.10.constraint.class_id=renewGracePeriodConstraintImpl\npolicyset.userCertSet.10.constraint.name=Renewal Grace Period Constraint\npolicyset.userCertSet.10.constraint.params.renewal.graceBefore=30\npolicyset.userCertSet.10.constraint.params.renewal.graceAfter=30\npolicyset.userCertSet.10.default.class_id=noDefaultImpl\npolicyset.userCertSet.10.default.name=No Default\npolicyset.userCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.userCertSet.2.constraint.name=Validity Constraint\npolicyset.userCertSet.2.constraint.params.range=365\npolicyset.userCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.userCertSet.2.constraint.params.notAfterCheck=false\npolicyset.userCertSet.2.default.class_id=validityDefaultImpl\npolicyset.userCertSet.2.default.name=Validity Default\npolicyset.userCertSet.2.default.params.range=180\npolicyset.userCertSet.2.default.params.startTime=0\npolicyset.userCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.userCertSet.3.constraint.name=Key Constraint\npolicyset.userCertSet.3.constraint.params.keyType=-\npolicyset.userCertSet.3.constraint.params.keyParameters=nistp256,nistp384,nistp521\npolicyset.userCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.userCertSet.3.default.name=Key Default\npolicyset.userCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.4.constraint.name=No Constraint\npolicyset.userCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.userCertSet.4.default.name=Authority Key Identifier Default\npolicyset.userCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.5.constraint.name=No Constraint\npolicyset.userCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.userCertSet.5.default.name=AIA Extension Default\npolicyset.userCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.userCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.userCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.userCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.userCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.userCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.userCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.userCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.userCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.userCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.userCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyAgreement=true\npolicyset.userCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.userCertSet.6.default.name=Key Usage Default\npolicyset.userCertSet.6.default.params.keyUsageCritical=true\npolicyset.userCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.userCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.userCertSet.6.default.params.keyUsageKeyAgreement=true\npolicyset.userCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.7.constraint.name=No Constraint\npolicyset.userCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.userCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.userCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.userCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.userCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.8.constraint.name=No Constraint\npolicyset.userCertSet.8.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.userCertSet.8.default.name=Subject Alt Name Constraint\npolicyset.userCertSet.8.default.params.subjAltNameExtCritical=false\npolicyset.userCertSet.8.default.params.subjAltExtType_0=RFC822Name\npolicyset.userCertSet.8.default.params.subjAltExtPattern_0=$request.requestor_email$\npolicyset.userCertSet.8.default.params.subjAltExtGNEnable_0=true\npolicyset.userCertSet.8.default.params.subjAltNameNumGNs=1\npolicyset.userCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.userCertSet.9.constraint.name=No Constraint\npolicyset.userCertSet.9.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.userCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.userCertSet.9.default.name=Signing Alg\npolicyset.userCertSet.9.default.params.signingAlg=-\nprofileId=caECDirPinUserCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:19Z DEBUG response status 409 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:19Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:19Z DEBUG Error migrating 'caECDirPinUserCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:19Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caECDirPinUserCert?action=enable 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 500 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:19 GMT Connection: close 2019-01-17T11:04:19Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:19Z DEBUG Failed to enable profile 'caECDirPinUserCert' (it is probably already enabled) 2019-01-17T11:04:19Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 204 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=0AF05AE8C4B3CB6B2290452C35EE72E1; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:19Z DEBUG response body '' 2019-01-17T11:04:19Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 200 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=B8AA759FF110ED55B69D767E6947005C; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:19Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:19Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:19Z DEBUG request body 'desc=This certificate profile is for enrolling user certificates with directory-based authentication.\nvisible=true\nenable=true\nenableBy=admin\nname=Directory-Authenticated User Dual-Use Certificate Enrollment\nauth.instance_id=UserDirEnrollment\ninput.list=i1\ninput.i1.class_id=keyGenInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=userCertSet\npolicyset.userCertSet.list=1,10,2,3,4,5,6,7,8,9\npolicyset.userCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.userCertSet.1.constraint.name=Subject Name Constraint\npolicyset.userCertSet.1.constraint.params.pattern=(UID|CN)=.*\npolicyset.userCertSet.1.constraint.params.accept=true\npolicyset.userCertSet.1.default.class_id=authTokenSubjectNameDefaultImpl\npolicyset.userCertSet.1.default.name=Subject Name Default\npolicyset.userCertSet.1.default.params.name=\npolicyset.userCertSet.10.constraint.class_id=renewGracePeriodConstraintImpl\npolicyset.userCertSet.10.constraint.name=Renewal Grace Period Constraint\npolicyset.userCertSet.10.constraint.params.renewal.graceBefore=30\npolicyset.userCertSet.10.constraint.params.renewal.graceAfter=30\npolicyset.userCertSet.10.default.class_id=noDefaultImpl\npolicyset.userCertSet.10.default.name=No Default\npolicyset.userCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.userCertSet.2.constraint.name=Validity Constraint\npolicyset.userCertSet.2.constraint.params.range=365\npolicyset.userCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.userCertSet.2.constraint.params.notAfterCheck=false\npolicyset.userCertSet.2.default.class_id=validityDefaultImpl\npolicyset.userCertSet.2.default.name=Validity Default\npolicyset.userCertSet.2.default.params.range=180\npolicyset.userCertSet.2.default.params.startTime=0\npolicyset.userCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.userCertSet.3.constraint.name=Key Constraint\npolicyset.userCertSet.3.constraint.params.keyType=RSA\npolicyset.userCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.userCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.userCertSet.3.default.name=Key Default\npolicyset.userCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.4.constraint.name=No Constraint\npolicyset.userCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.userCertSet.4.default.name=Authority Key Identifier Default\npolicyset.userCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.5.constraint.name=No Constraint\npolicyset.userCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.userCertSet.5.default.name=AIA Extension Default\npolicyset.userCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.userCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.userCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.userCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.userCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.userCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.userCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.userCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.userCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.userCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.userCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.userCertSet.6.default.name=Key Usage Default\npolicyset.userCertSet.6.default.params.keyUsageCritical=true\npolicyset.userCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.userCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.userCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.userCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.7.constraint.name=No Constraint\npolicyset.userCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.userCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.userCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.userCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.userCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.8.constraint.name=No Constraint\npolicyset.userCertSet.8.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.userCertSet.8.default.name=Subject Alt Name Constraint\npolicyset.userCertSet.8.default.params.subjAltNameExtCritical=false\npolicyset.userCertSet.8.default.params.subjAltExtType_0=RFC822Name\npolicyset.userCertSet.8.default.params.subjAltExtPattern_0=$request.requestor_email$\npolicyset.userCertSet.8.default.params.subjAltExtGNEnable_0=true\npolicyset.userCertSet.8.default.params.subjAltNameNumGNs=1\npolicyset.userCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.userCertSet.9.constraint.name=No Constraint\npolicyset.userCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.userCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.userCertSet.9.default.name=Signing Alg\npolicyset.userCertSet.9.default.params.signingAlg=-\nprofileId=caDirUserCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:19Z DEBUG response status 409 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:19Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:19Z DEBUG Error migrating 'caDirUserCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:19Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caDirUserCert?action=enable 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 500 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:19 GMT Connection: close 2019-01-17T11:04:19Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:19Z DEBUG Failed to enable profile 'caDirUserCert' (it is probably already enabled) 2019-01-17T11:04:19Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 204 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=24CB3C36941CCD5FA172E8172E0C9322; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:19Z DEBUG response body '' 2019-01-17T11:04:19Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 200 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=AF6ADDD841308BE38ADD4FA9D4FDFFDB; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:19Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:19Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:19Z DEBUG request body 'desc=This certificate profile is for enrolling user ECC certificates with directory-based authentication.\nvisible=true\nenable=true\nenableBy=admin\nname=Directory-Authenticated User ECC Certificate Enrollment\nauth.instance_id=UserDirEnrollment\ninput.list=i1\ninput.i1.class_id=keyGenInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=userCertSet\npolicyset.userCertSet.list=1,10,2,3,4,5,6,7,8,9\npolicyset.userCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.userCertSet.1.constraint.name=Subject Name Constraint\npolicyset.userCertSet.1.constraint.params.pattern=(UID|CN)=.*\npolicyset.userCertSet.1.constraint.params.accept=true\npolicyset.userCertSet.1.default.class_id=authTokenSubjectNameDefaultImpl\npolicyset.userCertSet.1.default.name=Subject Name Default\npolicyset.userCertSet.1.default.params.name=\npolicyset.userCertSet.10.constraint.class_id=renewGracePeriodConstraintImpl\npolicyset.userCertSet.10.constraint.name=Renewal Grace Period Constraint\npolicyset.userCertSet.10.constraint.params.renewal.graceBefore=30\npolicyset.userCertSet.10.constraint.params.renewal.graceAfter=30\npolicyset.userCertSet.10.default.class_id=noDefaultImpl\npolicyset.userCertSet.10.default.name=No Default\npolicyset.userCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.userCertSet.2.constraint.name=Validity Constraint\npolicyset.userCertSet.2.constraint.params.range=365\npolicyset.userCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.userCertSet.2.constraint.params.notAfterCheck=false\npolicyset.userCertSet.2.default.class_id=validityDefaultImpl\npolicyset.userCertSet.2.default.name=Validity Default\npolicyset.userCertSet.2.default.params.range=180\npolicyset.userCertSet.2.default.params.startTime=0\npolicyset.userCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.userCertSet.3.constraint.name=Key Constraint\npolicyset.userCertSet.3.constraint.params.keyType=EC\npolicyset.userCertSet.3.constraint.params.keyParameters=nistp256,nistp384,nistp521\npolicyset.userCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.userCertSet.3.default.name=Key Default\npolicyset.userCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.4.constraint.name=No Constraint\npolicyset.userCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.userCertSet.4.default.name=Authority Key Identifier Default\npolicyset.userCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.5.constraint.name=No Constraint\npolicyset.userCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.userCertSet.5.default.name=AIA Extension Default\npolicyset.userCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.userCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.userCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.userCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.userCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.userCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.userCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.userCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.userCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.userCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.userCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyAgreement=true\npolicyset.userCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.userCertSet.6.default.name=Key Usage Default\npolicyset.userCertSet.6.default.params.keyUsageCritical=true\npolicyset.userCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.userCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.userCertSet.6.default.params.keyUsageKeyAgreement=true\npolicyset.userCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.7.constraint.name=No Constraint\npolicyset.userCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.userCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.userCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.userCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.userCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.8.constraint.name=No Constraint\npolicyset.userCertSet.8.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.userCertSet.8.default.name=Subject Alt Name Constraint\npolicyset.userCertSet.8.default.params.subjAltNameExtCritical=false\npolicyset.userCertSet.8.default.params.subjAltExtType_0=RFC822Name\npolicyset.userCertSet.8.default.params.subjAltExtPattern_0=$request.requestor_email$\npolicyset.userCertSet.8.default.params.subjAltExtGNEnable_0=true\npolicyset.userCertSet.8.default.params.subjAltNameNumGNs=1\npolicyset.userCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.userCertSet.9.constraint.name=No Constraint\npolicyset.userCertSet.9.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.userCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.userCertSet.9.default.name=Signing Alg\npolicyset.userCertSet.9.default.params.signingAlg=-\nprofileId=caECDirUserCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:19Z DEBUG response status 409 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:19Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:19Z DEBUG Error migrating 'caECDirUserCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:19Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caECDirUserCert?action=enable 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 500 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:19 GMT Connection: close 2019-01-17T11:04:19Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:19Z DEBUG Failed to enable profile 'caECDirUserCert' (it is probably already enabled) 2019-01-17T11:04:19Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 204 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=B08F96C891E2DD4DAF2FAB0AC3CD5A67; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:19Z DEBUG response body '' 2019-01-17T11:04:19Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 200 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=C0312D2F8CC4284E0E92F926761F248F; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:19Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:19Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:19Z DEBUG request body 'desc=This certificate profile is for enrolling server certificates with agent authentication.\nvisible=true\nenable=true\nenableBy=admin\nauth.instance_id=AgentCertAuth\nname=Agent-Authenticated Server Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,12\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=365\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=180\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.12.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.12.constraint.name=No Constraint\npolicyset.serverCertSet.12.default.class_id=commonNameToSANDefaultImpl\npolicyset.serverCertSet.12.default.name=Copy Common Name to Subject Alternative Name Extension\nprofileId=caAgentServerCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:19Z DEBUG response status 409 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:19Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:19Z DEBUG Error migrating 'caAgentServerCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:19Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caAgentServerCert?action=enable 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 500 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:19 GMT Connection: close 2019-01-17T11:04:19Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:19Z DEBUG Failed to enable profile 'caAgentServerCert' (it is probably already enabled) 2019-01-17T11:04:19Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 204 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=D1976EDC04DFE5EB07AA7497E9F97E0C; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:19Z DEBUG response body '' 2019-01-17T11:04:19Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 200 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=8384FD6B89F056E019860525B667EA04; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:19Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:19Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:19Z DEBUG request body 'desc=This certificate profile is for enrolling server certificates with ECC keys using agent authentication.\nvisible=true\nenable=true\nenableBy=admin\nauth.instance_id=AgentCertAuth\nname=Agent-Authenticated Server Certificate Enrollment with ECC keys\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,12\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=365\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=180\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=-\npolicyset.serverCertSet.3.constraint.params.keyParameters=nistp256,nistp384,nistp521\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.12.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.12.constraint.name=No Constraint\npolicyset.serverCertSet.12.default.class_id=commonNameToSANDefaultImpl\npolicyset.serverCertSet.12.default.name=Copy Common Name to Subject Alternative Name Extension\nprofileId=caECAgentServerCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:19Z DEBUG response status 409 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:19Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:19Z DEBUG Error migrating 'caECAgentServerCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:19Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caECAgentServerCert?action=enable 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 500 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:19 GMT Connection: close 2019-01-17T11:04:19Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:19Z DEBUG Failed to enable profile 'caECAgentServerCert' (it is probably already enabled) 2019-01-17T11:04:19Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 204 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=86F4ED9DFDF19598084272ECDB5F7AED; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:19Z DEBUG response body '' 2019-01-17T11:04:19Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 200 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=B8E5DCE098BFC406725C8EA7E99A11F0; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:19Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:19Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:19Z DEBUG request body 'desc=This certificate profile is for getting file signing certificate with agent authentication.\nvisible=true\nenable=true\nenableBy=admin\nauth.instance_id=AgentCertAuth\nname=Agent-Authenticated File Signing\ninput.list=i1,i2,i3\ninput.i1.class_id=keyGenInputImpl\ninput.i2.class_id=fileSigningInputImpl\ninput.i3.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=pkcs7OutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=subjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=CN=(Name)$request.requestor_name$(Text)$request.file_signing_text$(Size)$request.file_signing_size$(DigestType)$request.file_signing_digest_type$(Digest)$request.file_signing_digest$\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=365\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=180\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.3\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\nprofileId=caAgentFileSigning\nclassId=caEnrollImpl\n' 2019-01-17T11:04:19Z DEBUG response status 409 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:19Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:19Z DEBUG Error migrating 'caAgentFileSigning': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:19Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caAgentFileSigning?action=enable 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 500 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:19 GMT Connection: close 2019-01-17T11:04:19Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:19Z DEBUG Failed to enable profile 'caAgentFileSigning' (it is probably already enabled) 2019-01-17T11:04:19Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 204 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=75DFA6385C5081809455B46DD643E30A; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:19Z DEBUG response body '' 2019-01-17T11:04:19Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 200 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=A5E990E4F4E51B4DEC323C04FB0B065D; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:19Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:19Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:19Z DEBUG request body 'desc=This certificate profile is for enrolling user certificates by using the CMC certificate request with CMC Signature authentication.\nvisible=true\nenable=true\nenableBy=admin\nauth.instance_id=CMCAuth\nauthz.acl=group="Certificate Manager Agents"\nname=Signed CMC-Authenticated User Certificate Enrollment\ninput.list=i1\ninput.i1.class_id=cmcCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=cmcUserCertSet\npolicyset.cmcUserCertSet.list=1,2,3,4,5,6,7,8\npolicyset.cmcUserCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.cmcUserCertSet.1.constraint.name=Subject Name Constraint\npolicyset.cmcUserCertSet.1.constraint.params.pattern=.*\npolicyset.cmcUserCertSet.1.constraint.params.accept=true\npolicyset.cmcUserCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.cmcUserCertSet.1.default.name=Subject Name Default\npolicyset.cmcUserCertSet.1.default.params.name=\npolicyset.cmcUserCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.cmcUserCertSet.2.constraint.name=Validity Constraint\npolicyset.cmcUserCertSet.2.constraint.params.range=365\npolicyset.cmcUserCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.cmcUserCertSet.2.constraint.params.notAfterCheck=false\npolicyset.cmcUserCertSet.2.default.class_id=validityDefaultImpl\npolicyset.cmcUserCertSet.2.default.name=Validity Default\npolicyset.cmcUserCertSet.2.default.params.range=180\npolicyset.cmcUserCertSet.2.default.params.startTime=0\npolicyset.cmcUserCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.cmcUserCertSet.3.constraint.name=Key Constraint\npolicyset.cmcUserCertSet.3.constraint.params.keyType=RSA\npolicyset.cmcUserCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.cmcUserCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.cmcUserCertSet.3.default.name=Key Default\npolicyset.cmcUserCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.4.constraint.name=No Constraint\npolicyset.cmcUserCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.cmcUserCertSet.4.default.name=Authority Key Identifier Default\npolicyset.cmcUserCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.5.constraint.name=No Constraint\npolicyset.cmcUserCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.cmcUserCertSet.5.default.name=AIA Extension Default\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.cmcUserCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.cmcUserCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.6.default.name=Key Usage Default\npolicyset.cmcUserCertSet.6.default.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.7.constraint.name=No Constraint\npolicyset.cmcUserCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.cmcUserCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.cmcUserCertSet.8.constraint.name=No Constraint\npolicyset.cmcUserCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.cmcUserCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.cmcUserCertSet.8.default.name=Signing Alg\npolicyset.cmcUserCertSet.8.default.params.signingAlg=-\nprofileId=caCMCUserCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:19Z DEBUG response status 409 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:19Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:19Z DEBUG Error migrating 'caCMCUserCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:19Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caCMCUserCert?action=enable 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:19Z DEBUG response status 500 2019-01-17T11:04:19Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:19 GMT Connection: close 2019-01-17T11:04:19Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:19Z DEBUG Failed to enable profile 'caCMCUserCert' (it is probably already enabled) 2019-01-17T11:04:19Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:19Z DEBUG request body '' 2019-01-17T11:04:20Z DEBUG response status 204 2019-01-17T11:04:20Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=15CE9C97CD75375E277BBC9F9B3CE2A4; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:20Z DEBUG response body '' 2019-01-17T11:04:20Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:20Z DEBUG request body '' 2019-01-17T11:04:20Z DEBUG response status 200 2019-01-17T11:04:20Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=D6D42FC667F8F39B614906F3ABD99818; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:20Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:20Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:20Z DEBUG request body 'desc=This certificate profile is for enrolling user certificates with ECC keys by using the CMC certificate request with CMC Signature authentication.\nvisible=true\nenable=true\nenableBy=admin\nauth.instance_id=CMCAuth\nauthz.acl=group="Certificate Manager Agents"\nname=Signed CMC-Authenticated User Certificate wth ECC keys Enrollment\ninput.list=i1\ninput.i1.class_id=cmcCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=cmcUserCertSet\npolicyset.cmcUserCertSet.list=1,2,3,4,5,6,7,8\npolicyset.cmcUserCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.cmcUserCertSet.1.constraint.name=Subject Name Constraint\npolicyset.cmcUserCertSet.1.constraint.params.pattern=.*\npolicyset.cmcUserCertSet.1.constraint.params.accept=true\npolicyset.cmcUserCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.cmcUserCertSet.1.default.name=Subject Name Default\npolicyset.cmcUserCertSet.1.default.params.name=\npolicyset.cmcUserCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.cmcUserCertSet.2.constraint.name=Validity Constraint\npolicyset.cmcUserCertSet.2.constraint.params.range=365\npolicyset.cmcUserCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.cmcUserCertSet.2.constraint.params.notAfterCheck=false\npolicyset.cmcUserCertSet.2.default.class_id=validityDefaultImpl\npolicyset.cmcUserCertSet.2.default.name=Validity Default\npolicyset.cmcUserCertSet.2.default.params.range=180\npolicyset.cmcUserCertSet.2.default.params.startTime=0\npolicyset.cmcUserCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.cmcUserCertSet.3.constraint.name=Key Constraint\npolicyset.cmcUserCertSet.3.constraint.params.keyType=EC\npolicyset.cmcUserCertSet.3.constraint.params.keyParameters=nistp256,nistp521\npolicyset.cmcUserCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.cmcUserCertSet.3.default.name=Key Default\npolicyset.cmcUserCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.4.constraint.name=No Constraint\npolicyset.cmcUserCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.cmcUserCertSet.4.default.name=Authority Key Identifier Default\npolicyset.cmcUserCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.5.constraint.name=No Constraint\npolicyset.cmcUserCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.cmcUserCertSet.5.default.name=AIA Extension Default\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.cmcUserCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.cmcUserCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyAgreement=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.6.default.name=Key Usage Default\npolicyset.cmcUserCertSet.6.default.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyAgreement=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.7.constraint.name=No Constraint\npolicyset.cmcUserCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.cmcUserCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.cmcUserCertSet.8.constraint.name=No Constraint\npolicyset.cmcUserCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.cmcUserCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.cmcUserCertSet.8.default.name=Signing Alg\npolicyset.cmcUserCertSet.8.default.params.signingAlg=-\nprofileId=caCMCECUserCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:20Z DEBUG response status 409 2019-01-17T11:04:20Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:20Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:20Z DEBUG Error migrating 'caCMCECUserCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:20Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caCMCECUserCert?action=enable 2019-01-17T11:04:20Z DEBUG request body '' 2019-01-17T11:04:20Z DEBUG response status 500 2019-01-17T11:04:20Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:19 GMT Connection: close 2019-01-17T11:04:20Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:20Z DEBUG Failed to enable profile 'caCMCECUserCert' (it is probably already enabled) 2019-01-17T11:04:20Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:20Z DEBUG request body '' 2019-01-17T11:04:20Z DEBUG response status 204 2019-01-17T11:04:20Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=97BAE1729B6C2E87B572949137BE3CD3; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:20Z DEBUG response body '' 2019-01-17T11:04:20Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:20Z DEBUG request body '' 2019-01-17T11:04:20Z DEBUG response status 200 2019-01-17T11:04:20Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=CC893AE265805C8FCC0A7637758F3EE9; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:20Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:20Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:20Z DEBUG request body 'desc=This certificate profile is for enrolling user certificates by using the agent-signed CMC certificate request with CMC Signature authentication.\nenable=true\nenableBy=admin\nname=Agent-Signed CMC-Authenticated User Certificate Enrollment\nvisible=false\nauth.instance_id=CMCAuth\nauthz.acl=group="Certificate Manager Agents"\ninput.list=i1\ninput.i1.class_id=cmcCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=cmcUserCertSet\npolicyset.cmcUserCertSet.list=1,2,3,4,5,6,7,8\npolicyset.cmcUserCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.cmcUserCertSet.1.constraint.name=Subject Name Constraint\npolicyset.cmcUserCertSet.1.constraint.params.accept=true\npolicyset.cmcUserCertSet.1.constraint.params.pattern=.*\npolicyset.cmcUserCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.cmcUserCertSet.1.default.name=Subject Name Default\npolicyset.cmcUserCertSet.1.default.params.name=\npolicyset.cmcUserCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.cmcUserCertSet.2.constraint.name=Validity Constraint\npolicyset.cmcUserCertSet.2.constraint.params.notAfterCheck=false\npolicyset.cmcUserCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.cmcUserCertSet.2.constraint.params.range=365\npolicyset.cmcUserCertSet.2.default.class_id=validityDefaultImpl\npolicyset.cmcUserCertSet.2.default.name=Validity Default\npolicyset.cmcUserCertSet.2.default.params.range=180\npolicyset.cmcUserCertSet.2.default.params.startTime=0\npolicyset.cmcUserCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.cmcUserCertSet.3.constraint.name=Key Constraint\npolicyset.cmcUserCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.cmcUserCertSet.3.constraint.params.keyType=RSA\npolicyset.cmcUserCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.cmcUserCertSet.3.default.name=Key Default\npolicyset.cmcUserCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.4.constraint.name=No Constraint\npolicyset.cmcUserCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.cmcUserCertSet.4.default.name=Authority Key Identifier Default\npolicyset.cmcUserCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.5.constraint.name=No Constraint\npolicyset.cmcUserCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.cmcUserCertSet.5.default.name=AIA Extension Default\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.cmcUserCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.cmcUserCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.6.default.name=Key Usage Default\npolicyset.cmcUserCertSet.6.default.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.7.constraint.name=No Constraint\npolicyset.cmcUserCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.cmcUserCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.cmcUserCertSet.8.constraint.name=No Constraint\npolicyset.cmcUserCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.cmcUserCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.cmcUserCertSet.8.default.name=Signing Alg\npolicyset.cmcUserCertSet.8.default.params.signingAlg=-\nprofileId=caFullCMCUserCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:20Z DEBUG response status 409 2019-01-17T11:04:20Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:20Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:20Z DEBUG Error migrating 'caFullCMCUserCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:20Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caFullCMCUserCert?action=enable 2019-01-17T11:04:20Z DEBUG request body '' 2019-01-17T11:04:20Z DEBUG response status 500 2019-01-17T11:04:20Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:19 GMT Connection: close 2019-01-17T11:04:20Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:20Z DEBUG Failed to enable profile 'caFullCMCUserCert' (it is probably already enabled) 2019-01-17T11:04:20Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:20Z DEBUG request body '' 2019-01-17T11:04:20Z DEBUG response status 204 2019-01-17T11:04:20Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=15704D9DB0A64555C60BB6DC727880D1; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:20Z DEBUG response body '' 2019-01-17T11:04:20Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:20Z DEBUG request body '' 2019-01-17T11:04:20Z DEBUG response status 200 2019-01-17T11:04:20Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=F1E9F6F875EEBF8AD42C98AB233A3224; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:20Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:20Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:20Z DEBUG request body 'desc=This certificate profile is for enrolling user certificates by using the agent-signed CMC certificate request with CMC Signature authentication.\nenable=true\nenableBy=admin\nname=Agent-Signed CMC-Authenticated User Certificate Enrollment\nvisible=false\nauth.instance_id=CMCAuth\nauthz.acl=group="Certificate Manager Agents"\ninput.list=i1\ninput.i1.class_id=cmcCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=cmcUserCertSet\npolicyset.cmcUserCertSet.list=1,2,3,4,5,6,7,8\npolicyset.cmcUserCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.cmcUserCertSet.1.constraint.name=Subject Name Constraint\npolicyset.cmcUserCertSet.1.constraint.params.accept=true\npolicyset.cmcUserCertSet.1.constraint.params.pattern=.*\npolicyset.cmcUserCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.cmcUserCertSet.1.default.name=Subject Name Default\npolicyset.cmcUserCertSet.1.default.params.name=\npolicyset.cmcUserCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.cmcUserCertSet.2.constraint.name=Validity Constraint\npolicyset.cmcUserCertSet.2.constraint.params.notAfterCheck=false\npolicyset.cmcUserCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.cmcUserCertSet.2.constraint.params.range=365\npolicyset.cmcUserCertSet.2.default.class_id=validityDefaultImpl\npolicyset.cmcUserCertSet.2.default.name=Validity Default\npolicyset.cmcUserCertSet.2.default.params.range=180\npolicyset.cmcUserCertSet.2.default.params.startTime=0\npolicyset.cmcUserCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.cmcUserCertSet.3.constraint.name=Key Constraint\npolicyset.cmcUserCertSet.3.constraint.params.keyParameters=nistp256,nistp521\npolicyset.cmcUserCertSet.3.constraint.params.keyType=EC\npolicyset.cmcUserCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.cmcUserCertSet.3.default.name=Key Default\npolicyset.cmcUserCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.4.constraint.name=No Constraint\npolicyset.cmcUserCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.cmcUserCertSet.4.default.name=Authority Key Identifier Default\npolicyset.cmcUserCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.5.constraint.name=No Constraint\npolicyset.cmcUserCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.cmcUserCertSet.5.default.name=AIA Extension Default\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.cmcUserCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.cmcUserCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyAgreement=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.6.default.name=Key Usage Default\npolicyset.cmcUserCertSet.6.default.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyAgreement=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.7.constraint.name=No Constraint\npolicyset.cmcUserCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.cmcUserCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.cmcUserCertSet.8.constraint.name=No Constraint\npolicyset.cmcUserCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.cmcUserCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.cmcUserCertSet.8.default.name=Signing Alg\npolicyset.cmcUserCertSet.8.default.params.signingAlg=-\nprofileId=caECFullCMCUserCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:20Z DEBUG response status 409 2019-01-17T11:04:20Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:20Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:20Z DEBUG Error migrating 'caECFullCMCUserCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:20Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caECFullCMCUserCert?action=enable 2019-01-17T11:04:20Z DEBUG request body '' 2019-01-17T11:04:20Z DEBUG response status 500 2019-01-17T11:04:20Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:19 GMT Connection: close 2019-01-17T11:04:20Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:20Z DEBUG Failed to enable profile 'caECFullCMCUserCert' (it is probably already enabled) 2019-01-17T11:04:20Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:20Z DEBUG request body '' 2019-01-17T11:04:20Z DEBUG response status 204 2019-01-17T11:04:20Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=ECC87971A4958A6E9290543DFEC0056F; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:20Z DEBUG response body '' 2019-01-17T11:04:20Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:20Z DEBUG request body '' 2019-01-17T11:04:20Z DEBUG response status 200 2019-01-17T11:04:20Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=42DE84B8B97D73571C3D764DECA2FE62; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:20Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:20Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:20Z DEBUG request body 'desc=This certificate profile is for enrolling user certificates by using the CMC certificate request with non-agent user CMC authentication.\nenable=false\nenableBy=admin\nname=User-Signed CMC-Authenticated User Certificate Enrollment\nvisible=false\nauth.instance_id=CMCUserSignedAuth\ninput.list=i1\ninput.i1.class_id=cmcCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=cmcUserCertSet\npolicyset.cmcUserCertSet.list=1,9,10,2,3,4,5,6,7,8\npolicyset.cmcUserCertSet.1.constraint.class_id=cmcUserSignedSubjectNameConstraintImpl\npolicyset.cmcUserCertSet.1.constraint.name=CMC User Signed Subject Name Constraint\npolicyset.cmcUserCertSet.1.default.class_id=cmcUserSignedSubjectNameDefaultImpl\npolicyset.cmcUserCertSet.1.default.name=User Signed Subject Name Default\npolicyset.cmcUserCertSet.1.default.params.name=\npolicyset.cmcUserCertSet.9.constraint.class_id=uniqueKeyConstraintImpl\npolicyset.cmcUserCertSet.9.constraint.name=Unique Key Constraint\npolicyset.cmcUserCertSet.9.constraint.params.allowSameKeyRenewal=true\npolicyset.cmcUserCertSet.9.default.class_id=noDefaultImpl\npolicyset.cmcUserCertSet.9.default.name=No Default\npolicyset.cmcUserCertSet.10.constraint.class_id=renewGracePeriodConstraintImpl\npolicyset.cmcUserCertSet.10.constraint.name=Renewal Grace Period Constraint\npolicyset.cmcUserCertSet.10.constraint.params.renewal.graceBefore=30\npolicyset.cmcUserCertSet.10.constraint.params.renewal.graceAfter=30\npolicyset.cmcUserCertSet.10.default.class_id=noDefaultImpl\npolicyset.cmcUserCertSet.10.default.name=No Default\npolicyset.cmcUserCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.cmcUserCertSet.2.constraint.name=Validity Constraint\npolicyset.cmcUserCertSet.2.constraint.params.notAfterCheck=false\npolicyset.cmcUserCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.cmcUserCertSet.2.constraint.params.range=365\npolicyset.cmcUserCertSet.2.default.class_id=validityDefaultImpl\npolicyset.cmcUserCertSet.2.default.name=Validity Default\npolicyset.cmcUserCertSet.2.default.params.range=180\npolicyset.cmcUserCertSet.2.default.params.startTime=0\npolicyset.cmcUserCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.cmcUserCertSet.3.constraint.name=Key Constraint\npolicyset.cmcUserCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.cmcUserCertSet.3.constraint.params.keyType=RSA\npolicyset.cmcUserCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.cmcUserCertSet.3.default.name=Key Default\npolicyset.cmcUserCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.4.constraint.name=No Constraint\npolicyset.cmcUserCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.cmcUserCertSet.4.default.name=Authority Key Identifier Default\npolicyset.cmcUserCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.5.constraint.name=No Constraint\npolicyset.cmcUserCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.cmcUserCertSet.5.default.name=AIA Extension Default\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.cmcUserCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.cmcUserCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.6.default.name=Key Usage Default\npolicyset.cmcUserCertSet.6.default.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.7.constraint.name=No Constraint\npolicyset.cmcUserCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.cmcUserCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.cmcUserCertSet.8.constraint.name=No Constraint\npolicyset.cmcUserCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.cmcUserCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.cmcUserCertSet.8.default.name=Signing Alg\npolicyset.cmcUserCertSet.8.default.params.signingAlg=-\nprofileId=caFullCMCUserSignedCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:20Z DEBUG response status 409 2019-01-17T11:04:20Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:20Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:20Z DEBUG Error migrating 'caFullCMCUserSignedCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:20Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caFullCMCUserSignedCert?action=enable 2019-01-17T11:04:20Z DEBUG request body '' 2019-01-17T11:04:20Z DEBUG response status 500 2019-01-17T11:04:20Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:19 GMT Connection: close 2019-01-17T11:04:20Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:20Z DEBUG Failed to enable profile 'caFullCMCUserSignedCert' (it is probably already enabled) 2019-01-17T11:04:20Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:20Z DEBUG request body '' 2019-01-17T11:04:20Z DEBUG response status 204 2019-01-17T11:04:20Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=6A5DE8149904D9B9D0F9D4D5D4A997CE; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:20Z DEBUG response body '' 2019-01-17T11:04:20Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:20Z DEBUG request body '' 2019-01-17T11:04:20Z DEBUG response status 200 2019-01-17T11:04:20Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=7EDB9946CA4B5369A1142D39619EC1E9; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:20Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:20Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:20Z DEBUG request body 'desc=This certificate profile is for enrolling user certificates with EC keys by using the CMC certificate request with non-agent user CMC authentication.\nenable=false\nenableBy=admin\nname=User-Signed CMC-Authenticated User Certificate Enrollment\nvisible=false\nauth.instance_id=CMCUserSignedAuth\ninput.list=i1\ninput.i1.class_id=cmcCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=cmcUserCertSet\npolicyset.cmcUserCertSet.list=1,9,10,2,3,4,5,6,7,8\npolicyset.cmcUserCertSet.1.constraint.class_id=cmcUserSignedSubjectNameConstraintImpl\npolicyset.cmcUserCertSet.1.constraint.name=CMC User Signed Subject Name Constraint\npolicyset.cmcUserCertSet.1.default.class_id=cmcUserSignedSubjectNameDefaultImpl\npolicyset.cmcUserCertSet.1.default.name=User Signed Subject Name Default\npolicyset.cmcUserCertSet.1.default.params.name=\npolicyset.cmcUserCertSet.9.constraint.class_id=uniqueKeyConstraintImpl\npolicyset.cmcUserCertSet.9.constraint.name=Unique Key Constraint\npolicyset.cmcUserCertSet.9.constraint.params.allowSameKeyRenewal=true\npolicyset.cmcUserCertSet.9.default.class_id=noDefaultImpl\npolicyset.cmcUserCertSet.9.default.name=No Default\npolicyset.cmcUserCertSet.10.constraint.class_id=renewGracePeriodConstraintImpl\npolicyset.cmcUserCertSet.10.constraint.name=Renewal Grace Period Constraint\npolicyset.cmcUserCertSet.10.constraint.params.renewal.graceBefore=30\npolicyset.cmcUserCertSet.10.constraint.params.renewal.graceAfter=30\npolicyset.cmcUserCertSet.10.default.class_id=noDefaultImpl\npolicyset.cmcUserCertSet.10.default.name=No Default\npolicyset.cmcUserCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.cmcUserCertSet.2.constraint.name=Validity Constraint\npolicyset.cmcUserCertSet.2.constraint.params.notAfterCheck=false\npolicyset.cmcUserCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.cmcUserCertSet.2.constraint.params.range=365\npolicyset.cmcUserCertSet.2.default.class_id=validityDefaultImpl\npolicyset.cmcUserCertSet.2.default.name=Validity Default\npolicyset.cmcUserCertSet.2.default.params.range=180\npolicyset.cmcUserCertSet.2.default.params.startTime=0\npolicyset.cmcUserCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.cmcUserCertSet.3.constraint.name=Key Constraint\npolicyset.cmcUserCertSet.3.constraint.params.keyParameters=nistp256,nistp521\npolicyset.cmcUserCertSet.3.constraint.params.keyType=EC\npolicyset.cmcUserCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.cmcUserCertSet.3.default.name=Key Default\npolicyset.cmcUserCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.4.constraint.name=No Constraint\npolicyset.cmcUserCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.cmcUserCertSet.4.default.name=Authority Key Identifier Default\npolicyset.cmcUserCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.5.constraint.name=No Constraint\npolicyset.cmcUserCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.cmcUserCertSet.5.default.name=AIA Extension Default\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.cmcUserCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.cmcUserCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyAgreement=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.6.default.name=Key Usage Default\npolicyset.cmcUserCertSet.6.default.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyAgreement=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.7.constraint.name=No Constraint\npolicyset.cmcUserCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.cmcUserCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.cmcUserCertSet.8.constraint.name=No Constraint\npolicyset.cmcUserCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.cmcUserCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.cmcUserCertSet.8.default.name=Signing Alg\npolicyset.cmcUserCertSet.8.default.params.signingAlg=-\nprofileId=caECFullCMCUserSignedCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:20Z DEBUG response status 409 2019-01-17T11:04:20Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:20Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:20Z DEBUG Error migrating 'caECFullCMCUserSignedCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:20Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caECFullCMCUserSignedCert?action=enable 2019-01-17T11:04:20Z DEBUG request body '' 2019-01-17T11:04:20Z DEBUG response status 500 2019-01-17T11:04:20Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:19 GMT Connection: close 2019-01-17T11:04:20Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:20Z DEBUG Failed to enable profile 'caECFullCMCUserSignedCert' (it is probably already enabled) 2019-01-17T11:04:20Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:20Z DEBUG request body '' 2019-01-17T11:04:20Z DEBUG response status 204 2019-01-17T11:04:20Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=00F3D663E65E4268BD0A10F3EBCC14D4; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:20Z DEBUG response body '' 2019-01-17T11:04:20Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:20Z DEBUG request body '' 2019-01-17T11:04:20Z DEBUG response status 200 2019-01-17T11:04:20Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=8942027CE729D6BA3D1E93C0A801842C; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:20Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:20Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:20Z DEBUG request body 'desc=This certificate profile is for enrolling user certificates by using the self-signed CMC certificate request\nenable=false\nenableBy=admin\nname=Self-Signed CMC User Certificate Enrollment\nvisible=false\nauth.instance_id=CMCUserSignedAuth\ninput.list=i1\ninput.i1.class_id=cmcCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=cmcUserCertSet\npolicyset.cmcUserCertSet.list=1,2,3,4,5,6,7,8\npolicyset.cmcUserCertSet.1.constraint.class_id=cmcSelfSignedSubjectNameConstraintImpl\npolicyset.cmcUserCertSet.1.constraint.name=CMC Self-Signed Subject Name Constraint\npolicyset.cmcUserCertSet.1.default.class_id=authTokenSubjectNameDefaultImpl\npolicyset.cmcUserCertSet.1.default.name=Subject Name Default\npolicyset.cmcUserCertSet.1.default.params.name=\npolicyset.cmcUserCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.cmcUserCertSet.2.constraint.name=Validity Constraint\npolicyset.cmcUserCertSet.2.constraint.params.notAfterCheck=false\npolicyset.cmcUserCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.cmcUserCertSet.2.constraint.params.range=365\npolicyset.cmcUserCertSet.2.default.class_id=validityDefaultImpl\npolicyset.cmcUserCertSet.2.default.name=Validity Default\npolicyset.cmcUserCertSet.2.default.params.range=180\npolicyset.cmcUserCertSet.2.default.params.startTime=0\npolicyset.cmcUserCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.cmcUserCertSet.3.constraint.name=Key Constraint\npolicyset.cmcUserCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.cmcUserCertSet.3.constraint.params.keyType=RSA\npolicyset.cmcUserCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.cmcUserCertSet.3.default.name=Key Default\npolicyset.cmcUserCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.4.constraint.name=No Constraint\npolicyset.cmcUserCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.cmcUserCertSet.4.default.name=Authority Key Identifier Default\npolicyset.cmcUserCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.5.constraint.name=No Constraint\npolicyset.cmcUserCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.cmcUserCertSet.5.default.name=AIA Extension Default\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.cmcUserCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.cmcUserCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.6.default.name=Key Usage Default\npolicyset.cmcUserCertSet.6.default.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.7.constraint.name=No Constraint\npolicyset.cmcUserCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.cmcUserCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.cmcUserCertSet.8.constraint.name=No Constraint\npolicyset.cmcUserCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.cmcUserCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.cmcUserCertSet.8.default.name=Signing Alg\npolicyset.cmcUserCertSet.8.default.params.signingAlg=-\nprofileId=caFullCMCSelfSignedCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:20Z DEBUG response status 409 2019-01-17T11:04:20Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:20Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:20Z DEBUG Error migrating 'caFullCMCSelfSignedCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:20Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caFullCMCSelfSignedCert?action=enable 2019-01-17T11:04:20Z DEBUG request body '' 2019-01-17T11:04:20Z DEBUG response status 500 2019-01-17T11:04:20Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:19 GMT Connection: close 2019-01-17T11:04:20Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:20Z DEBUG Failed to enable profile 'caFullCMCSelfSignedCert' (it is probably already enabled) 2019-01-17T11:04:20Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:20Z DEBUG request body '' 2019-01-17T11:04:20Z DEBUG response status 204 2019-01-17T11:04:20Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=B058E6E6D68A380353370CFA4A10CBEA; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:20Z DEBUG response body '' 2019-01-17T11:04:20Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:20Z DEBUG request body '' 2019-01-17T11:04:20Z DEBUG response status 200 2019-01-17T11:04:20Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=0C8F1A9AE32A24856E9EE7F35A8671FE; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:20Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:20Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:20Z DEBUG request body 'desc=This certificate profile is for enrolling user certificates with ECC keys by using the self-signed CMC certificate request\nenable=false\nenableBy=admin\nname=Self-Signed CMC User Certificate Enrollment\nvisible=false\nauth.instance_id=CMCUserSignedAuth\ninput.list=i1\ninput.i1.class_id=cmcCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=cmcUserCertSet\npolicyset.cmcUserCertSet.list=1,2,3,4,5,6,7,8\npolicyset.cmcUserCertSet.1.constraint.class_id=cmcSelfSignedSubjectNameConstraintImpl\npolicyset.cmcUserCertSet.1.constraint.name=CMC User-Signed Subject Name Constraint\npolicyset.cmcUserCertSet.1.default.class_id=authTokenSubjectNameDefaultImpl\npolicyset.cmcUserCertSet.1.default.name=Subject Name Default\npolicyset.cmcUserCertSet.1.default.params.name=\npolicyset.cmcUserCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.cmcUserCertSet.2.constraint.name=Validity Constraint\npolicyset.cmcUserCertSet.2.constraint.params.notAfterCheck=false\npolicyset.cmcUserCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.cmcUserCertSet.2.constraint.params.range=365\npolicyset.cmcUserCertSet.2.default.class_id=validityDefaultImpl\npolicyset.cmcUserCertSet.2.default.name=Validity Default\npolicyset.cmcUserCertSet.2.default.params.range=180\npolicyset.cmcUserCertSet.2.default.params.startTime=0\npolicyset.cmcUserCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.cmcUserCertSet.3.constraint.name=Key Constraint\npolicyset.cmcUserCertSet.3.constraint.params.keyParameters=nistp256,nistp521\npolicyset.cmcUserCertSet.3.constraint.params.keyType=EC\npolicyset.cmcUserCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.cmcUserCertSet.3.default.name=Key Default\npolicyset.cmcUserCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.4.constraint.name=No Constraint\npolicyset.cmcUserCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.cmcUserCertSet.4.default.name=Authority Key Identifier Default\npolicyset.cmcUserCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.5.constraint.name=No Constraint\npolicyset.cmcUserCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.cmcUserCertSet.5.default.name=AIA Extension Default\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.cmcUserCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.cmcUserCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyAgreement=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.6.default.name=Key Usage Default\npolicyset.cmcUserCertSet.6.default.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyAgreement=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.7.constraint.name=No Constraint\npolicyset.cmcUserCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.cmcUserCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.cmcUserCertSet.8.constraint.name=No Constraint\npolicyset.cmcUserCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.cmcUserCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.cmcUserCertSet.8.default.name=Signing Alg\npolicyset.cmcUserCertSet.8.default.params.signingAlg=-\nprofileId=caECFullCMCSelfSignedCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:20Z DEBUG response status 409 2019-01-17T11:04:20Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:19 GMT 2019-01-17T11:04:20Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:20Z DEBUG Error migrating 'caECFullCMCSelfSignedCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:20Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caECFullCMCSelfSignedCert?action=enable 2019-01-17T11:04:20Z DEBUG request body '' 2019-01-17T11:04:20Z DEBUG response status 500 2019-01-17T11:04:20Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:19 GMT Connection: close 2019-01-17T11:04:20Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:20Z DEBUG Failed to enable profile 'caECFullCMCSelfSignedCert' (it is probably already enabled) 2019-01-17T11:04:20Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:20Z DEBUG request body '' 2019-01-17T11:04:21Z DEBUG response status 204 2019-01-17T11:04:21Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=A233EA978D686F4717CE8E234DD5A956; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:21 GMT 2019-01-17T11:04:21Z DEBUG response body '' 2019-01-17T11:04:21Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:21Z DEBUG request body '' 2019-01-17T11:04:21Z DEBUG response status 200 2019-01-17T11:04:21Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=080DB3F2295138C17BC518474770943E; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:21 GMT 2019-01-17T11:04:21Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:21Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:21Z DEBUG request body 'desc=This certificate profile is for enrolling user certificates by using the CMC Simple certificate request with agent authentication.\nenable=true\nenableBy=admin\nname=Simple CMC Enrollment Request for User Certificate\nvisible=false\nauth.instance_id=AgentCertAuth\ninput.list=i1\ninput.i1.class_id=certReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=cmcUserCertSet\npolicyset.cmcUserCertSet.list=1,2,3,4,5,6,7,8\npolicyset.cmcUserCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.cmcUserCertSet.1.constraint.name=Subject Name Constraint\npolicyset.cmcUserCertSet.1.constraint.params.accept=true\npolicyset.cmcUserCertSet.1.constraint.params.pattern=.*\npolicyset.cmcUserCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.cmcUserCertSet.1.default.name=Subject Name Default\npolicyset.cmcUserCertSet.1.default.params.name=\npolicyset.cmcUserCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.cmcUserCertSet.2.constraint.name=Validity Constraint\npolicyset.cmcUserCertSet.2.constraint.params.notAfterCheck=false\npolicyset.cmcUserCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.cmcUserCertSet.2.constraint.params.range=365\npolicyset.cmcUserCertSet.2.default.class_id=validityDefaultImpl\npolicyset.cmcUserCertSet.2.default.name=Validity Default\npolicyset.cmcUserCertSet.2.default.params.range=180\npolicyset.cmcUserCertSet.2.default.params.startTime=0\npolicyset.cmcUserCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.cmcUserCertSet.3.constraint.name=Key Constraint\npolicyset.cmcUserCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.cmcUserCertSet.3.constraint.params.keyType=RSA\npolicyset.cmcUserCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.cmcUserCertSet.3.default.name=Key Default\npolicyset.cmcUserCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.4.constraint.name=No Constraint\npolicyset.cmcUserCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.cmcUserCertSet.4.default.name=Authority Key Identifier Default\npolicyset.cmcUserCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.5.constraint.name=No Constraint\npolicyset.cmcUserCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.cmcUserCertSet.5.default.name=AIA Extension Default\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.cmcUserCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.cmcUserCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.6.default.name=Key Usage Default\npolicyset.cmcUserCertSet.6.default.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.7.constraint.name=No Constraint\npolicyset.cmcUserCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.cmcUserCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.cmcUserCertSet.8.constraint.name=No Constraint\npolicyset.cmcUserCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.cmcUserCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.cmcUserCertSet.8.default.name=Signing Alg\npolicyset.cmcUserCertSet.8.default.params.signingAlg=-\nprofileId=caSimpleCMCUserCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:21Z DEBUG response status 409 2019-01-17T11:04:21Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:21 GMT 2019-01-17T11:04:21Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:21Z DEBUG Error migrating 'caSimpleCMCUserCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:21Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caSimpleCMCUserCert?action=enable 2019-01-17T11:04:21Z DEBUG request body '' 2019-01-17T11:04:21Z DEBUG response status 500 2019-01-17T11:04:21Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:21 GMT Connection: close 2019-01-17T11:04:21Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:21Z DEBUG Failed to enable profile 'caSimpleCMCUserCert' (it is probably already enabled) 2019-01-17T11:04:21Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:21Z DEBUG request body '' 2019-01-17T11:04:21Z DEBUG response status 204 2019-01-17T11:04:21Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=8BE9B5AB158075A7CF09E39B25EDF287; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:21 GMT 2019-01-17T11:04:21Z DEBUG response body '' 2019-01-17T11:04:21Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:21Z DEBUG request body '' 2019-01-17T11:04:21Z DEBUG response status 200 2019-01-17T11:04:21Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=19DA2ADC4E6738111C40E2E83F735F0F; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:21 GMT 2019-01-17T11:04:21Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:21Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:21Z DEBUG request body 'desc=This certificate profile is for enrolling user certificates by using the CMC simple certificate request with agent authentication.\nenable=true\nenableBy=admin\nname=Simple CMC Enrollment Request for User Certificate\nvisible=false\nauth.instance_id=AgentCertAuth\ninput.list=i1\ninput.i1.class_id=certReqInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=cmcUserCertSet\npolicyset.cmcUserCertSet.list=1,2,3,4,5,6,7,8\npolicyset.cmcUserCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.cmcUserCertSet.1.constraint.name=Subject Name Constraint\npolicyset.cmcUserCertSet.1.constraint.params.accept=true\npolicyset.cmcUserCertSet.1.constraint.params.pattern=.*\npolicyset.cmcUserCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.cmcUserCertSet.1.default.name=Subject Name Default\npolicyset.cmcUserCertSet.1.default.params.name=\npolicyset.cmcUserCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.cmcUserCertSet.2.constraint.name=Validity Constraint\npolicyset.cmcUserCertSet.2.constraint.params.notAfterCheck=false\npolicyset.cmcUserCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.cmcUserCertSet.2.constraint.params.range=365\npolicyset.cmcUserCertSet.2.default.class_id=validityDefaultImpl\npolicyset.cmcUserCertSet.2.default.name=Validity Default\npolicyset.cmcUserCertSet.2.default.params.range=180\npolicyset.cmcUserCertSet.2.default.params.startTime=0\npolicyset.cmcUserCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.cmcUserCertSet.3.constraint.name=Key Constraint\npolicyset.cmcUserCertSet.3.constraint.params.keyParameters=nistp256,nistp521\npolicyset.cmcUserCertSet.3.constraint.params.keyType=EC\npolicyset.cmcUserCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.cmcUserCertSet.3.default.name=Key Default\npolicyset.cmcUserCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.4.constraint.name=No Constraint\npolicyset.cmcUserCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.cmcUserCertSet.4.default.name=Authority Key Identifier Default\npolicyset.cmcUserCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.5.constraint.name=No Constraint\npolicyset.cmcUserCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.cmcUserCertSet.5.default.name=AIA Extension Default\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.cmcUserCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.cmcUserCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.cmcUserCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyAgreement=true\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.cmcUserCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.6.default.name=Key Usage Default\npolicyset.cmcUserCertSet.6.default.params.keyUsageCritical=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyAgreement=true\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.cmcUserCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.cmcUserCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.cmcUserCertSet.7.constraint.name=No Constraint\npolicyset.cmcUserCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.cmcUserCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.cmcUserCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.cmcUserCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.cmcUserCertSet.8.constraint.name=No Constraint\npolicyset.cmcUserCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.cmcUserCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.cmcUserCertSet.8.default.name=Signing Alg\npolicyset.cmcUserCertSet.8.default.params.signingAlg=-\nprofileId=caECSimpleCMCUserCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:21Z DEBUG response status 409 2019-01-17T11:04:21Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:21 GMT 2019-01-17T11:04:21Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:21Z DEBUG Error migrating 'caECSimpleCMCUserCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:21Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caECSimpleCMCUserCert?action=enable 2019-01-17T11:04:21Z DEBUG request body '' 2019-01-17T11:04:21Z DEBUG response status 500 2019-01-17T11:04:21Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:21 GMT Connection: close 2019-01-17T11:04:21Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:21Z DEBUG Failed to enable profile 'caECSimpleCMCUserCert' (it is probably already enabled) 2019-01-17T11:04:21Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:21Z DEBUG request body '' 2019-01-17T11:04:21Z DEBUG response status 204 2019-01-17T11:04:21Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=261A77DD496BD0C60255183849E07AA0; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:21 GMT 2019-01-17T11:04:21Z DEBUG response body '' 2019-01-17T11:04:21Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:21Z DEBUG request body '' 2019-01-17T11:04:21Z DEBUG response status 200 2019-01-17T11:04:21Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=A9380C4D6F6A32D97036C70EAE31A619; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:21 GMT 2019-01-17T11:04:21Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:21Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:21Z DEBUG request body 'desc=This profile is for enrolling token device keys\nenable=true\nenableBy=admin\nlastModified=1068835451090\nname=Token Device Key Enrollment\nvisible=false\nauth.instance_id=AgentCertAuth\ninput.list=i1\ninput.i1.class_id=nsHKeyCertReqInputImpl\ninput.i1.name=nsHKeyCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=nsNKeyOutputImpl\noutput.o2.name=nsNKeyOutputImpl\npolicyset.list=set1\n#policyset.set1.list=p2,p3,p4,p5,p1,p7,p8,p9,p12,p6\npolicyset.set1.list=p2,p4,p5,p1,p8,p9,p12\npolicyset.set1.p1.constraint.class_id=noConstraintImpl\npolicyset.set1.p1.constraint.name=No Constraint\npolicyset.set1.p1.default.class_id=nsTokenDeviceKeySubjectNameDefaultImpl\npolicyset.set1.p1.default.name=nsTokenDeviceKeySubjectNameDefault\npolicyset.set1.p1.default.params.dnpattern=UID=Token Key Device - $request.tokencuid$\npolicyset.set1.p12.constraint.class_id=basicConstraintsExtConstraintImpl\npolicyset.set1.p12.constraint.name=Basic Constraints Extension Constraint\npolicyset.set1.p12.constraint.params.basicConstraintsCritical=-\npolicyset.set1.p12.constraint.params.basicConstraintsIsCA=-\npolicyset.set1.p12.constraint.params.basicConstraintsMaxPathLen=-1\npolicyset.set1.p12.constraint.params.basicConstraintsMinPathLen=-1\npolicyset.set1.p12.default.class_id=basicConstraintsExtDefaultImpl\npolicyset.set1.p12.default.name=Basic Constraints Extension Default\npolicyset.set1.p12.default.params.basicConstraintsCritical=false\npolicyset.set1.p12.default.params.basicConstraintsIsCA=false\npolicyset.set1.p12.default.params.basicConstraintsPathLen=-1\npolicyset.set1.p2.constraint.class_id=noConstraintImpl\npolicyset.set1.p2.constraint.name=No Constraint\npolicyset.set1.p2.default.class_id=validityDefaultImpl\npolicyset.set1.p2.default.name=Validity Default\npolicyset.set1.p2.default.params.range=1825\npolicyset.set1.p2.default.params.startTime=0\npolicyset.set1.p3.constraint.class_id=noConstraintImpl\npolicyset.set1.p3.constraint.name=No Constraint\npolicyset.set1.p3.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.set1.p3.default.name=crlDistributionPointsExtDefaultImpl\npolicyset.set1.p3.default.params.crlDistPointsCritical=false\npolicyset.set1.p3.default.params.crlDistPointsNum=1\npolicyset.set1.p3.default.params.crlDistPointsEnable_0=false\npolicyset.set1.p3.default.params.crlDistPointsIssuerName_0=\npolicyset.set1.p3.default.params.crlDistPointsIssuerType_0=\npolicyset.set1.p3.default.params.crlDistPointsPointName_0=\npolicyset.set1.p3.default.params.crlDistPointsPointType_0=URIName\npolicyset.set1.p3.default.params.crlDistPointsReasons_0=\npolicyset.set1.p4.constraint.class_id=noConstraintImpl\npolicyset.set1.p4.constraint.name=No Constraint\npolicyset.set1.p4.default.class_id=signingAlgDefaultImpl\npolicyset.set1.p4.default.name=Signing Algorithm Default\npolicyset.set1.p4.default.params.signingAlg=-\npolicyset.set1.p5.constraint.class_id=noConstraintImpl\npolicyset.set1.p5.constraint.name=No Constraint\npolicyset.set1.p5.default.class_id=keyUsageExtDefaultImpl\npolicyset.set1.p5.default.name=Key Usage Extension Default\npolicyset.set1.p5.default.params.keyUsageCritical=true\npolicyset.set1.p5.default.params.keyUsageCrlSign=false\npolicyset.set1.p5.default.params.keyUsageDataEncipherment=false\npolicyset.set1.p5.default.params.keyUsageDecipherOnly=false\npolicyset.set1.p5.default.params.keyUsageDigitalSignature=true\npolicyset.set1.p5.default.params.keyUsageEncipherOnly=false\npolicyset.set1.p5.default.params.keyUsageKeyAgreement=false\npolicyset.set1.p5.default.params.keyUsageKeyCertSign=false\npolicyset.set1.p5.default.params.keyUsageKeyEncipherment=false\npolicyset.set1.p5.default.params.keyUsageNonRepudiation=false\npolicyset.set1.p7.constraint.class_id=noConstraintImpl\npolicyset.set1.p7.constraint.name=No Constraint\npolicyset.set1.p7.default.class_id=certificatePoliciesExtDefaultImpl\npolicyset.set1.p7.default.name=Certificate Policies Extension Default\npolicyset.set1.p7.default.params.Critical=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p8.constraint.class_id=noConstraintImpl\npolicyset.set1.p8.constraint.name=No Constraint\npolicyset.set1.p8.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.set1.p8.default.name=Subject Key Identifier Default\npolicyset.set1.p9.constraint.class_id=noConstraintImpl\npolicyset.set1.p9.constraint.name=No Constraint\npolicyset.set1.p9.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.set1.p9.default.name=Authority Key Identifier Extension Default\npolicyset.set1.p6.constraint.class_id=noConstraintImpl\npolicyset.set1.p6.constraint.name=No Constraint\npolicyset.set1.p6.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.set1.p6.default.name=Subject Alternative Name Extension Default\npolicyset.set1.p6.default.params.subjAltExtGNEnable_0=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_1=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_2=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_3=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_4=false\npolicyset.set1.p6.default.params.subjAltExtPattern_0=\npolicyset.set1.p6.default.params.subjAltExtPattern_1=\npolicyset.set1.p6.default.params.subjAltExtPattern_2=\npolicyset.set1.p6.default.params.subjAltExtPattern_3=\npolicyset.set1.p6.default.params.subjAltExtPattern_4=\npolicyset.set1.p6.default.params.subjAltExtType_0=OtherName\npolicyset.set1.p6.default.params.subjAltExtType_1=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_2=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_3=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_4=RFC822Name\npolicyset.set1.p6.default.params.subjAltNameExtCritical=false\npolicyset.set1.p6.default.params.subjAltNameNumGNs=1\nprofileId=caTokenDeviceKeyEnrollment\nclassId=caUserCertEnrollImpl\n' 2019-01-17T11:04:21Z DEBUG response status 409 2019-01-17T11:04:21Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:21 GMT 2019-01-17T11:04:21Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:21Z DEBUG Error migrating 'caTokenDeviceKeyEnrollment': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:21Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caTokenDeviceKeyEnrollment?action=enable 2019-01-17T11:04:21Z DEBUG request body '' 2019-01-17T11:04:21Z DEBUG response status 500 2019-01-17T11:04:21Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:21 GMT Connection: close 2019-01-17T11:04:21Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:21Z DEBUG Failed to enable profile 'caTokenDeviceKeyEnrollment' (it is probably already enabled) 2019-01-17T11:04:21Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:21Z DEBUG request body '' 2019-01-17T11:04:21Z DEBUG response status 204 2019-01-17T11:04:21Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=7513279B1610DB0A6CBE45A6E4F5631C; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:21 GMT 2019-01-17T11:04:21Z DEBUG response body '' 2019-01-17T11:04:21Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:21Z DEBUG request body '' 2019-01-17T11:04:21Z DEBUG response status 200 2019-01-17T11:04:21Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=1006E2631B375FDB0CB0A38C13F18542; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:21 GMT 2019-01-17T11:04:21Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:21Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:21Z DEBUG request body 'desc=This profile is for enrolling Token Encryption key\nenable=true\nenableBy=admin\nname=Token User Encryption Certificate Enrollment\nvisible=false\nauth.instance_id=AgentCertAuth\ninput.list=i1\ninput.i1.class_id=nsNKeyCertReqInputImpl\ninput.i1.name=nsNKeyCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=nsNKeyOutputImpl\noutput.o2.name=nsNKeyOutputImpl\npolicyset.list=set1\n#policyset.set1.list=p2,p4,p5,p1,p6,p7,p8,p9,p12,p13,p14\npolicyset.set1.list=p2,p4,p5,p1,p6,p8,p9,p12\npolicyset.set1.p1.constraint.class_id=noConstraintImpl\npolicyset.set1.p1.constraint.name=No Constraint\npolicyset.set1.p1.default.class_id=nsTokenUserKeySubjectNameDefaultImpl\npolicyset.set1.p1.default.name=nsTokenUserKeySubjectNameDefault\npolicyset.set1.p1.default.params.dnpattern=UID=$request.uid$, O=Token Key User\n#changed ldap.enable to true to support SMIME\npolicyset.set1.p1.default.params.ldap.enable=false\npolicyset.set1.p1.default.params.ldap.searchName=uid\npolicyset.set1.p1.default.params.ldapStringAttributes=uid,mail\npolicyset.set1.p1.default.params.ldap.basedn=\npolicyset.set1.p1.default.params.ldap.maxConns=4\npolicyset.set1.p1.default.params.ldap.minConns=1\npolicyset.set1.p1.default.params.ldap.ldapconn.Version=2\npolicyset.set1.p1.default.params.ldap.ldapconn.host=\npolicyset.set1.p1.default.params.ldap.ldapconn.port=\npolicyset.set1.p1.default.params.ldap.ldapconn.secureConn=false\npolicyset.set1.p2.constraint.class_id=noConstraintImpl\npolicyset.set1.p2.constraint.name=No Constraint\npolicyset.set1.p2.default.class_id=validityDefaultImpl\npolicyset.set1.p2.default.name=Validity Default\npolicyset.set1.p2.default.params.range=1825\npolicyset.set1.p2.default.params.startTime=0\npolicyset.set1.p4.constraint.class_id=noConstraintImpl\npolicyset.set1.p4.constraint.name=No Constraint\npolicyset.set1.p4.default.class_id=signingAlgDefaultImpl\npolicyset.set1.p4.default.name=Signing Algorithm Default\npolicyset.set1.p4.default.params.signingAlg=-\npolicyset.set1.p5.constraint.class_id=noConstraintImpl\npolicyset.set1.p5.constraint.name=No Constraint\npolicyset.set1.p5.default.class_id=keyUsageExtDefaultImpl\npolicyset.set1.p5.default.name=Key Usage Extension Default\npolicyset.set1.p5.default.params.keyUsageCritical=true\npolicyset.set1.p5.default.params.keyUsageCrlSign=false\npolicyset.set1.p5.default.params.keyUsageDataEncipherment=false\npolicyset.set1.p5.default.params.keyUsageDecipherOnly=false\npolicyset.set1.p5.default.params.keyUsageDigitalSignature=false\npolicyset.set1.p5.default.params.keyUsageEncipherOnly=false\npolicyset.set1.p5.default.params.keyUsageKeyAgreement=false\npolicyset.set1.p5.default.params.keyUsageKeyCertSign=false\npolicyset.set1.p5.default.params.keyUsageKeyEncipherment=true\npolicyset.set1.p5.default.params.keyUsageNonRepudiation=false\npolicyset.set1.p6.constraint.class_id=noConstraintImpl\npolicyset.set1.p6.constraint.name=No Constraint\npolicyset.set1.p6.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.set1.p6.default.name=Subject Alternative Name Extension Default\npolicyset.set1.p6.default.params.subjAltExtGNEnable_0=true\npolicyset.set1.p6.default.params.subjAltExtGNEnable_1=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_2=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_3=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_4=false\npolicyset.set1.p6.default.params.subjAltExtPattern_0=$request.mail$\npolicyset.set1.p6.default.params.subjAltExtPattern_1=\npolicyset.set1.p6.default.params.subjAltExtPattern_2=\npolicyset.set1.p6.default.params.subjAltExtPattern_3=\npolicyset.set1.p6.default.params.subjAltExtPattern_4=\npolicyset.set1.p6.default.params.subjAltExtType_0=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_1=OtherName\npolicyset.set1.p6.default.params.subjAltExtType_2=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_3=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_4=RFC822Name\npolicyset.set1.p6.default.params.subjAltNameExtCritical=false\npolicyset.set1.p6.default.params.subjAltNameNumGNs=1\npolicyset.set1.p7.constraint.class_id=noConstraintImpl\npolicyset.set1.p7.constraint.name=No Constraint\npolicyset.set1.p7.default.class_id=certificatePoliciesExtDefaultImpl\npolicyset.set1.p7.default.name=Certificate Policies Extension Default\npolicyset.set1.p7.default.params.Critical=false\npolicyset.set1.p7.default.params.PoliciesExt.num=5\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.CPSURI.enable=true\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p8.constraint.class_id=noConstraintImpl\npolicyset.set1.p8.constraint.name=No Constraint\npolicyset.set1.p8.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.set1.p8.default.name=Subject Key Identifier Default\npolicyset.set1.p9.constraint.class_id=noConstraintImpl\npolicyset.set1.p9.constraint.name=No Constraint\npolicyset.set1.p9.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.set1.p9.default.name=Authority Key Identifier Extension Default\npolicyset.set1.10.constraint.class_id=renewGracePeriodConstraintImpl\npolicyset.set1.10.constraint.name=Renewal Grace Period Constraint\npolicyset.set1.10.constraint.params.renewal.graceBefore=30\npolicyset.set1.10.constraint.params.renewal.graceAfter=30\npolicyset.set1.10.default.class_id=noDefaultImpl\npolicyset.set1.10.default.name=No Default\npolicyset.set1.p12.constraint.class_id=basicConstraintsExtConstraintImpl\npolicyset.set1.p12.constraint.name=Basic Constraints Extension Constraint\npolicyset.set1.p12.constraint.params.basicConstraintsCritical=-\npolicyset.set1.p12.constraint.params.basicConstraintsIsCA=-\npolicyset.set1.p12.constraint.params.basicConstraintsMaxPathLen=-1\npolicyset.set1.p12.constraint.params.basicConstraintsMinPathLen=-1\npolicyset.set1.p12.default.class_id=basicConstraintsExtDefaultImpl\npolicyset.set1.p12.default.name=Basic Constraints Extension Default\npolicyset.set1.p12.default.params.basicConstraintsCritical=false\npolicyset.set1.p12.default.params.basicConstraintsIsCA=false\npolicyset.set1.p12.default.params.basicConstraintsPathLen=-1\npolicyset.set1.p13.constraint.class_id=noConstraintImpl\npolicyset.set1.p13.constraint.name=No Constraint\npolicyset.set1.p13.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.set1.p13.default.name=crlDistributionPointsExtDefaultImpl\npolicyset.set1.p13.default.params.crlDistPointsCritical=false\npolicyset.set1.p13.default.params.crlDistPointsNum=1\npolicyset.set1.p13.default.params.crlDistPointsEnable_0=false\npolicyset.set1.p13.default.params.crlDistPointsIssuerName_0=\npolicyset.set1.p13.default.params.crlDistPointsIssuerType_0=\npolicyset.set1.p13.default.params.crlDistPointsPointName_0=\npolicyset.set1.p13.default.params.crlDistPointsPointType_0=URIName\npolicyset.set1.p13.default.params.crlDistPointsReasons_0=\npolicyset.set1.p14.constraint.class_id=noConstraintImpl\npolicyset.set1.p14.constraint.name=No Constraint\npolicyset.set1.p14.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.set1.p14.default.name=AIA Extension Default\npolicyset.set1.p14.default.params.authInfoAccessADEnable_0=false\npolicyset.set1.p14.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.set1.p14.default.params.authInfoAccessADLocation_0=\npolicyset.set1.p14.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.set1.p14.default.params.authInfoAccessCritical=false\npolicyset.set1.p14.default.params.authInfoAccessNumADs=1\nprofileId=caTokenUserEncryptionKeyEnrollment\nclassId=caUserCertEnrollImpl\n' 2019-01-17T11:04:21Z DEBUG response status 409 2019-01-17T11:04:21Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:21 GMT 2019-01-17T11:04:21Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:21Z DEBUG Error migrating 'caTokenUserEncryptionKeyEnrollment': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:21Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caTokenUserEncryptionKeyEnrollment?action=enable 2019-01-17T11:04:21Z DEBUG request body '' 2019-01-17T11:04:21Z DEBUG response status 500 2019-01-17T11:04:21Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:21 GMT Connection: close 2019-01-17T11:04:21Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:21Z DEBUG Failed to enable profile 'caTokenUserEncryptionKeyEnrollment' (it is probably already enabled) 2019-01-17T11:04:21Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:21Z DEBUG request body '' 2019-01-17T11:04:21Z DEBUG response status 204 2019-01-17T11:04:21Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=06A11090C87121AC36CD1415C2547C69; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:21 GMT 2019-01-17T11:04:21Z DEBUG response body '' 2019-01-17T11:04:21Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:21Z DEBUG request body '' 2019-01-17T11:04:21Z DEBUG response status 200 2019-01-17T11:04:21Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=7EA3236D6938B6560E4BDAC521950C02; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:21 GMT 2019-01-17T11:04:21Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:21Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:21Z DEBUG request body 'desc=This profile is for enrolling Token Signing key\nenable=true\nenableBy=admin\nname=Token User Signing Certificate Enrollment\nvisible=false\nauth.instance_id=AgentCertAuth\ninput.list=i1\ninput.i1.class_id=nsNKeyCertReqInputImpl\ninput.i1.name=nsNKeyCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=nsNKeyOutputImpl\noutput.o2.name=nsNKeyOutputImpl\npolicyset.list=set1\n#policyset.set1.list=p2,p4,p5,p1,p6,p7,p8,p9,p12,p13,p14\npolicyset.set1.list=p2,p4,p5,p1,p6,p8,p9,p12\npolicyset.set1.p1.constraint.class_id=noConstraintImpl\npolicyset.set1.p1.constraint.name=No Constraint\npolicyset.set1.p1.default.class_id=nsTokenUserKeySubjectNameDefaultImpl\npolicyset.set1.p1.default.name=nsTokenUserKeySubjectNameDefault\npolicyset.set1.p1.default.params.dnpattern=UID=$request.uid$, O=Token Key User\n#changed ldap.enable to true to support SMIME\npolicyset.set1.p1.default.params.ldap.enable=false\npolicyset.set1.p1.default.params.ldap.searchName=uid\npolicyset.set1.p1.default.params.ldapStringAttributes=uid,mail\npolicyset.set1.p1.default.params.ldap.basedn=\npolicyset.set1.p1.default.params.ldap.maxConns=4\npolicyset.set1.p1.default.params.ldap.minConns=1\npolicyset.set1.p1.default.params.ldap.ldapconn.Version=2\npolicyset.set1.p1.default.params.ldap.ldapconn.host=\npolicyset.set1.p1.default.params.ldap.ldapconn.port=\npolicyset.set1.p1.default.params.ldap.ldapconn.secureConn=false\npolicyset.set1.p2.constraint.class_id=noConstraintImpl\npolicyset.set1.p2.constraint.name=No Constraint\npolicyset.set1.p2.default.class_id=validityDefaultImpl\npolicyset.set1.p2.default.name=Validity Default\npolicyset.set1.p2.default.params.range=1825\npolicyset.set1.p2.default.params.startTime=0\npolicyset.set1.p4.constraint.class_id=noConstraintImpl\npolicyset.set1.p4.constraint.name=No Constraint\npolicyset.set1.p4.default.class_id=signingAlgDefaultImpl\npolicyset.set1.p4.default.name=Signing Algorithm Default\npolicyset.set1.p4.default.params.signingAlg=-\npolicyset.set1.p5.constraint.class_id=noConstraintImpl\npolicyset.set1.p5.constraint.name=No Constraint\npolicyset.set1.p5.default.class_id=keyUsageExtDefaultImpl\npolicyset.set1.p5.default.name=Key Usage Extension Default\npolicyset.set1.p5.default.params.keyUsageCritical=true\npolicyset.set1.p5.default.params.keyUsageCrlSign=false\npolicyset.set1.p5.default.params.keyUsageDataEncipherment=false\npolicyset.set1.p5.default.params.keyUsageDecipherOnly=false\npolicyset.set1.p5.default.params.keyUsageDigitalSignature=true\npolicyset.set1.p5.default.params.keyUsageEncipherOnly=false\npolicyset.set1.p5.default.params.keyUsageKeyAgreement=false\npolicyset.set1.p5.default.params.keyUsageKeyCertSign=false\npolicyset.set1.p5.default.params.keyUsageKeyEncipherment=false\npolicyset.set1.p5.default.params.keyUsageNonRepudiation=true\npolicyset.set1.p6.constraint.class_id=noConstraintImpl\npolicyset.set1.p6.constraint.name=No Constraint\npolicyset.set1.p6.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.set1.p6.default.name=Subject Alternative Name Extension Default\npolicyset.set1.p6.default.params.subjAltExtGNEnable_0=true\npolicyset.set1.p6.default.params.subjAltExtGNEnable_1=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_2=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_3=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_4=false\npolicyset.set1.p6.default.params.subjAltExtPattern_0=$request.mail$\npolicyset.set1.p6.default.params.subjAltExtPattern_1=\npolicyset.set1.p6.default.params.subjAltExtPattern_2=\npolicyset.set1.p6.default.params.subjAltExtPattern_3=\npolicyset.set1.p6.default.params.subjAltExtPattern_4=\npolicyset.set1.p6.default.params.subjAltExtType_0=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_1=OtherName\npolicyset.set1.p6.default.params.subjAltExtType_2=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_3=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_4=RFC822Name\npolicyset.set1.p6.default.params.subjAltNameExtCritical=false\npolicyset.set1.p6.default.params.subjAltNameNumGNs=1\npolicyset.set1.p7.constraint.class_id=noConstraintImpl\npolicyset.set1.p7.constraint.name=No Constraint\npolicyset.set1.p7.default.class_id=certificatePoliciesExtDefaultImpl\npolicyset.set1.p7.default.name=Certificate Policies Extension Default\npolicyset.set1.p7.default.params.Critical=false\npolicyset.set1.p7.default.params.PoliciesExt.num=5\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.CPSURI.enable=true\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p8.constraint.class_id=noConstraintImpl\npolicyset.set1.p8.constraint.name=No Constraint\npolicyset.set1.p8.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.set1.p8.default.name=Subject Key Identifier Default\npolicyset.set1.p9.constraint.class_id=noConstraintImpl\npolicyset.set1.p9.constraint.name=No Constraint\npolicyset.set1.p9.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.set1.p9.default.name=Authority Key Identifier Extension Default\npolicyset.set1.10.constraint.class_id=renewGracePeriodConstraintImpl\npolicyset.set1.10.constraint.name=Renewal Grace Period Constraint\npolicyset.set1.10.constraint.params.renewal.graceBefore=30\npolicyset.set1.10.constraint.params.renewal.graceAfter=30\npolicyset.set1.10.default.class_id=noDefaultImpl\npolicyset.set1.10.default.name=No Default\npolicyset.set1.p12.constraint.class_id=basicConstraintsExtConstraintImpl\npolicyset.set1.p12.constraint.name=Basic Constraints Extension Constraint\npolicyset.set1.p12.constraint.params.basicConstraintsCritical=-\npolicyset.set1.p12.constraint.params.basicConstraintsIsCA=-\npolicyset.set1.p12.constraint.params.basicConstraintsMaxPathLen=-1\npolicyset.set1.p12.constraint.params.basicConstraintsMinPathLen=-1\npolicyset.set1.p12.default.class_id=basicConstraintsExtDefaultImpl\npolicyset.set1.p12.default.name=Basic Constraints Extension Default\npolicyset.set1.p12.default.params.basicConstraintsCritical=false\npolicyset.set1.p12.default.params.basicConstraintsIsCA=false\npolicyset.set1.p12.default.params.basicConstraintsPathLen=-1\npolicyset.set1.p13.constraint.class_id=noConstraintImpl\npolicyset.set1.p13.constraint.name=No Constraint\npolicyset.set1.p13.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.set1.p13.default.name=crlDistributionPointsExtDefaultImpl\npolicyset.set1.p13.default.params.crlDistPointsCritical=false\npolicyset.set1.p13.default.params.crlDistPointsNum=1\npolicyset.set1.p13.default.params.crlDistPointsEnable_0=false\npolicyset.set1.p13.default.params.crlDistPointsIssuerName_0=\npolicyset.set1.p13.default.params.crlDistPointsIssuerType_0=\npolicyset.set1.p13.default.params.crlDistPointsPointName_0=\npolicyset.set1.p13.default.params.crlDistPointsPointType_0=URIName\npolicyset.set1.p13.default.params.crlDistPointsReasons_0=\npolicyset.set1.p14.constraint.class_id=noConstraintImpl\npolicyset.set1.p14.constraint.name=No Constraint\npolicyset.set1.p14.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.set1.p14.default.name=AIA Extension Default\npolicyset.set1.p14.default.params.authInfoAccessADEnable_0=false\npolicyset.set1.p14.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.set1.p14.default.params.authInfoAccessADLocation_0=\npolicyset.set1.p14.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.set1.p14.default.params.authInfoAccessCritical=false\npolicyset.set1.p14.default.params.authInfoAccessNumADs=1\nprofileId=caTokenUserSigningKeyEnrollment\nclassId=caUserCertEnrollImpl\n' 2019-01-17T11:04:21Z DEBUG response status 409 2019-01-17T11:04:21Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:21 GMT 2019-01-17T11:04:21Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:21Z DEBUG Error migrating 'caTokenUserSigningKeyEnrollment': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:21Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caTokenUserSigningKeyEnrollment?action=enable 2019-01-17T11:04:21Z DEBUG request body '' 2019-01-17T11:04:21Z DEBUG response status 500 2019-01-17T11:04:21Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:21 GMT Connection: close 2019-01-17T11:04:21Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:21Z DEBUG Failed to enable profile 'caTokenUserSigningKeyEnrollment' (it is probably already enabled) 2019-01-17T11:04:21Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:21Z DEBUG request body '' 2019-01-17T11:04:21Z DEBUG response status 204 2019-01-17T11:04:21Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=4A47C23BC5BEEE7529D15FFB41D56FCA; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:21 GMT 2019-01-17T11:04:21Z DEBUG response body '' 2019-01-17T11:04:21Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:21Z DEBUG request body '' 2019-01-17T11:04:21Z DEBUG response status 200 2019-01-17T11:04:21Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=CAE6972696C13B1D2812FAA45B152306; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:21 GMT 2019-01-17T11:04:21Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:21Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:21Z DEBUG request body 'desc=This profile is for enrolling token device keys\nenable=true\nenableBy=admin\nlastModified=1068835451090\nname=Temporary Device Certificate Enrollment\nvisible=false\nauth.instance_id=AgentCertAuth\ninput.list=i1\ninput.i1.class_id=nsHKeyCertReqInputImpl\ninput.i1.name=nsHKeyCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=nsNKeyOutputImpl\noutput.o2.name=nsNKeyOutputImpl\npolicyset.list=set1\n#policyset.set1.list=p2,p3,p4,p5,p1,p7,p8,p9,p12,p6\npolicyset.set1.list=p2,p4,p5,p1,p8,p9,p12\npolicyset.set1.p1.constraint.class_id=noConstraintImpl\npolicyset.set1.p1.constraint.name=No Constraint\npolicyset.set1.p1.default.class_id=nsTokenDeviceKeySubjectNameDefaultImpl\npolicyset.set1.p1.default.name=nsTokenDeviceKeySubjectNameDefault\npolicyset.set1.p1.default.params.dnpattern=UID=Token Key Device - $request.tokencuid$\npolicyset.set1.p12.constraint.class_id=basicConstraintsExtConstraintImpl\npolicyset.set1.p12.constraint.name=Basic Constraints Extension Constraint\npolicyset.set1.p12.constraint.params.basicConstraintsCritical=-\npolicyset.set1.p12.constraint.params.basicConstraintsIsCA=-\npolicyset.set1.p12.constraint.params.basicConstraintsMaxPathLen=-1\npolicyset.set1.p12.constraint.params.basicConstraintsMinPathLen=-1\npolicyset.set1.p12.default.class_id=basicConstraintsExtDefaultImpl\npolicyset.set1.p12.default.name=Basic Constraints Extension Default\npolicyset.set1.p12.default.params.basicConstraintsCritical=false\npolicyset.set1.p12.default.params.basicConstraintsIsCA=false\npolicyset.set1.p12.default.params.basicConstraintsPathLen=-1\npolicyset.set1.p2.constraint.class_id=noConstraintImpl\npolicyset.set1.p2.constraint.name=No Constraint\npolicyset.set1.p2.default.class_id=validityDefaultImpl\npolicyset.set1.p2.default.name=Validity Default\npolicyset.set1.p2.default.params.range=7\npolicyset.set1.p2.default.params.startTime=0\npolicyset.set1.p3.constraint.class_id=noConstraintImpl\npolicyset.set1.p3.constraint.name=No Constraint\npolicyset.set1.p3.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.set1.p3.default.name=crlDistributionPointsExtDefaultImpl\npolicyset.set1.p3.default.params.crlDistPointsCritical=false\npolicyset.set1.p3.default.params.crlDistPointsNum=1\npolicyset.set1.p3.default.params.crlDistPointsEnable_0=false\npolicyset.set1.p3.default.params.crlDistPointsIssuerName_0=\npolicyset.set1.p3.default.params.crlDistPointsIssuerType_0=\npolicyset.set1.p3.default.params.crlDistPointsPointName_0=\npolicyset.set1.p3.default.params.crlDistPointsPointType_0=URIName\npolicyset.set1.p3.default.params.crlDistPointsReasons_0=\npolicyset.set1.p4.constraint.class_id=noConstraintImpl\npolicyset.set1.p4.constraint.name=No Constraint\npolicyset.set1.p4.default.class_id=signingAlgDefaultImpl\npolicyset.set1.p4.default.name=Signing Algorithm Default\npolicyset.set1.p4.default.params.signingAlg=-\npolicyset.set1.p5.constraint.class_id=noConstraintImpl\npolicyset.set1.p5.constraint.name=No Constraint\npolicyset.set1.p5.default.class_id=keyUsageExtDefaultImpl\npolicyset.set1.p5.default.name=Key Usage Extension Default\npolicyset.set1.p5.default.params.keyUsageCritical=true\npolicyset.set1.p5.default.params.keyUsageCrlSign=false\npolicyset.set1.p5.default.params.keyUsageDataEncipherment=false\npolicyset.set1.p5.default.params.keyUsageDecipherOnly=false\npolicyset.set1.p5.default.params.keyUsageDigitalSignature=true\npolicyset.set1.p5.default.params.keyUsageEncipherOnly=false\npolicyset.set1.p5.default.params.keyUsageKeyAgreement=false\npolicyset.set1.p5.default.params.keyUsageKeyCertSign=false\npolicyset.set1.p5.default.params.keyUsageKeyEncipherment=false\npolicyset.set1.p5.default.params.keyUsageNonRepudiation=false\npolicyset.set1.p7.constraint.class_id=noConstraintImpl\npolicyset.set1.p7.constraint.name=No Constraint\npolicyset.set1.p7.default.class_id=certificatePoliciesExtDefaultImpl\npolicyset.set1.p7.default.name=Certificate Policies Extension Default\npolicyset.set1.p7.default.params.Critical=false\npolicyset.set1.p7.default.params.PoliciesExt.num=5\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p8.constraint.class_id=noConstraintImpl\npolicyset.set1.p8.constraint.name=No Constraint\npolicyset.set1.p8.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.set1.p8.default.name=Subject Key Identifier Default\npolicyset.set1.p9.constraint.class_id=noConstraintImpl\npolicyset.set1.p9.constraint.name=No Constraint\npolicyset.set1.p9.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.set1.p9.default.name=Authority Key Identifier Extension Default\npolicyset.set1.p6.constraint.class_id=noConstraintImpl\npolicyset.set1.p6.constraint.name=No Constraint\npolicyset.set1.p6.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.set1.p6.default.name=Subject Alternative Name Extension Default\npolicyset.set1.p6.default.params.subjAltExtGNEnable_0=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_1=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_2=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_3=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_4=false\npolicyset.set1.p6.default.params.subjAltExtPattern_0=\npolicyset.set1.p6.default.params.subjAltExtPattern_1=\npolicyset.set1.p6.default.params.subjAltExtPattern_2=\npolicyset.set1.p6.default.params.subjAltExtPattern_3=\npolicyset.set1.p6.default.params.subjAltExtPattern_4=\npolicyset.set1.p6.default.params.subjAltExtType_0=OtherName\npolicyset.set1.p6.default.params.subjAltExtType_1=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_2=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_3=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_4=RFC822Name\npolicyset.set1.p6.default.params.subjAltNameExtCritical=false\npolicyset.set1.p6.default.params.subjAltNameNumGNs=1\nprofileId=caTempTokenDeviceKeyEnrollment\nclassId=caUserCertEnrollImpl\n' 2019-01-17T11:04:21Z DEBUG response status 409 2019-01-17T11:04:21Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:21 GMT 2019-01-17T11:04:21Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:21Z DEBUG Error migrating 'caTempTokenDeviceKeyEnrollment': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:21Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caTempTokenDeviceKeyEnrollment?action=enable 2019-01-17T11:04:21Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 500 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:21 GMT Connection: close 2019-01-17T11:04:22Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:22Z DEBUG Failed to enable profile 'caTempTokenDeviceKeyEnrollment' (it is probably already enabled) 2019-01-17T11:04:22Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 204 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=985F21D8877AB28EFA4D2A900B044A65; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body '' 2019-01-17T11:04:22Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 200 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=CA28D93E095587404A662A6A7348CC2C; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:22Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:22Z DEBUG request body 'desc=This profile is for enrolling Token Encryption key\nenable=true\nenableBy=admin\nname=Temporary Token User Encryption Certificate Enrollment\nvisible=false\nauth.instance_id=AgentCertAuth\ninput.list=i1\ninput.i1.class_id=nsNKeyCertReqInputImpl\ninput.i1.name=nsNKeyCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=nsNKeyOutputImpl\noutput.o2.name=nsNKeyOutputImpl\npolicyset.list=set1\n#policyset.set1.list=p2,p4,p5,p1,p6,p7,p8,p9,p12,p13,p14\npolicyset.set1.list=p2,p4,p5,p1,p6,p8,p9,p12\npolicyset.set1.p1.constraint.class_id=noConstraintImpl\npolicyset.set1.p1.constraint.name=No Constraint\npolicyset.set1.p1.default.class_id=nsTokenUserKeySubjectNameDefaultImpl\npolicyset.set1.p1.default.name=nsTokenUserKeySubjectNameDefault\n#uncomment below to support SMIME\n#policyset.set1.p1.default.params.dnpattern=UID=$request.uid$, E=$request.mail$, O=Token Key User\npolicyset.set1.p1.default.params.dnpattern=UID=$request.uid$, O=Token Key User\n#changed ldap.enable to true to support SMIME\npolicyset.set1.p1.default.params.ldap.enable=false\npolicyset.set1.p1.default.params.ldap.searchName=uid\npolicyset.set1.p1.default.params.ldapStringAttributes=uid,mail\npolicyset.set1.p1.default.params.ldap.basedn=\npolicyset.set1.p1.default.params.ldap.maxConns=4\npolicyset.set1.p1.default.params.ldap.minConns=1\npolicyset.set1.p1.default.params.ldap.ldapconn.Version=2\npolicyset.set1.p1.default.params.ldap.ldapconn.host=\npolicyset.set1.p1.default.params.ldap.ldapconn.port=\npolicyset.set1.p1.default.params.ldap.ldapconn.secureConn=false\npolicyset.set1.p2.constraint.class_id=noConstraintImpl\npolicyset.set1.p2.constraint.name=No Constraint\npolicyset.set1.p2.default.class_id=validityDefaultImpl\npolicyset.set1.p2.default.name=Validity Default\npolicyset.set1.p2.default.params.range=7\npolicyset.set1.p2.default.params.startTime=0\npolicyset.set1.p4.constraint.class_id=noConstraintImpl\npolicyset.set1.p4.constraint.name=No Constraint\npolicyset.set1.p4.default.class_id=signingAlgDefaultImpl\npolicyset.set1.p4.default.name=Signing Algorithm Default\npolicyset.set1.p4.default.params.signingAlg=-\npolicyset.set1.p5.constraint.class_id=noConstraintImpl\npolicyset.set1.p5.constraint.name=No Constraint\npolicyset.set1.p5.default.class_id=keyUsageExtDefaultImpl\npolicyset.set1.p5.default.name=Key Usage Extension Default\npolicyset.set1.p5.default.params.keyUsageCritical=true\npolicyset.set1.p5.default.params.keyUsageCrlSign=false\npolicyset.set1.p5.default.params.keyUsageDataEncipherment=false\npolicyset.set1.p5.default.params.keyUsageDecipherOnly=false\npolicyset.set1.p5.default.params.keyUsageDigitalSignature=false\npolicyset.set1.p5.default.params.keyUsageEncipherOnly=false\npolicyset.set1.p5.default.params.keyUsageKeyAgreement=false\npolicyset.set1.p5.default.params.keyUsageKeyCertSign=false\npolicyset.set1.p5.default.params.keyUsageKeyEncipherment=true\npolicyset.set1.p5.default.params.keyUsageNonRepudiation=false\npolicyset.set1.p6.constraint.class_id=noConstraintImpl\npolicyset.set1.p6.constraint.name=No Constraint\npolicyset.set1.p6.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.set1.p6.default.name=Subject Alternative Name Extension Default\npolicyset.set1.p6.default.params.subjAltExtGNEnable_0=true\npolicyset.set1.p6.default.params.subjAltExtGNEnable_1=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_2=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_3=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_4=false\npolicyset.set1.p6.default.params.subjAltExtPattern_0=$request.mail$\npolicyset.set1.p6.default.params.subjAltExtPattern_1=\npolicyset.set1.p6.default.params.subjAltExtPattern_2=\npolicyset.set1.p6.default.params.subjAltExtPattern_3=\npolicyset.set1.p6.default.params.subjAltExtPattern_4=\npolicyset.set1.p6.default.params.subjAltExtType_0=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_1=OtherName\npolicyset.set1.p6.default.params.subjAltExtType_2=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_3=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_4=RFC822Name\npolicyset.set1.p6.default.params.subjAltNameExtCritical=false\npolicyset.set1.p6.default.params.subjAltNameNumGNs=1\npolicyset.set1.p7.constraint.class_id=noConstraintImpl\npolicyset.set1.p7.constraint.name=No Constraint\npolicyset.set1.p7.default.class_id=certificatePoliciesExtDefaultImpl\npolicyset.set1.p7.default.name=Certificate Policies Extension Default\npolicyset.set1.p7.default.params.Critical=false\npolicyset.set1.p7.default.params.PoliciesExt.num=5\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.CPSURI.enable=true\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p8.constraint.class_id=noConstraintImpl\npolicyset.set1.p8.constraint.name=No Constraint\npolicyset.set1.p8.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.set1.p8.default.name=Subject Key Identifier Default\npolicyset.set1.p9.constraint.class_id=noConstraintImpl\npolicyset.set1.p9.constraint.name=No Constraint\npolicyset.set1.p9.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.set1.p9.default.name=Authority Key Identifier Extension Default\npolicyset.set1.p12.constraint.class_id=basicConstraintsExtConstraintImpl\npolicyset.set1.p12.constraint.name=Basic Constraints Extension Constraint\npolicyset.set1.p12.constraint.params.basicConstraintsCritical=-\npolicyset.set1.p12.constraint.params.basicConstraintsIsCA=-\npolicyset.set1.p12.constraint.params.basicConstraintsMaxPathLen=-1\npolicyset.set1.p12.constraint.params.basicConstraintsMinPathLen=-1\npolicyset.set1.p12.default.class_id=basicConstraintsExtDefaultImpl\npolicyset.set1.p12.default.name=Basic Constraints Extension Default\npolicyset.set1.p12.default.params.basicConstraintsCritical=false\npolicyset.set1.p12.default.params.basicConstraintsIsCA=false\npolicyset.set1.p12.default.params.basicConstraintsPathLen=-1\npolicyset.set1.p13.constraint.class_id=noConstraintImpl\npolicyset.set1.p13.constraint.name=No Constraint\npolicyset.set1.p13.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.set1.p13.default.name=crlDistributionPointsExtDefaultImpl\npolicyset.set1.p13.default.params.crlDistPointsCritical=false\npolicyset.set1.p13.default.params.crlDistPointsNum=1\npolicyset.set1.p13.default.params.crlDistPointsEnable_0=false\npolicyset.set1.p13.default.params.crlDistPointsIssuerName_0=\npolicyset.set1.p13.default.params.crlDistPointsIssuerType_0=\npolicyset.set1.p13.default.params.crlDistPointsPointName_0=\npolicyset.set1.p13.default.params.crlDistPointsPointType_0=URIName\npolicyset.set1.p13.default.params.crlDistPointsReasons_0=\npolicyset.set1.p14.constraint.class_id=noConstraintImpl\npolicyset.set1.p14.constraint.name=No Constraint\npolicyset.set1.p14.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.set1.p14.default.name=AIA Extension Default\npolicyset.set1.p14.default.params.authInfoAccessADEnable_0=false\npolicyset.set1.p14.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.set1.p14.default.params.authInfoAccessADLocation_0=\npolicyset.set1.p14.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.set1.p14.default.params.authInfoAccessCritical=false\npolicyset.set1.p14.default.params.authInfoAccessNumADs=1\nprofileId=caTempTokenUserEncryptionKeyEnrollment\nclassId=caUserCertEnrollImpl\n' 2019-01-17T11:04:22Z DEBUG response status 409 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:22Z DEBUG Error migrating 'caTempTokenUserEncryptionKeyEnrollment': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:22Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caTempTokenUserEncryptionKeyEnrollment?action=enable 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 500 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:22 GMT Connection: close 2019-01-17T11:04:22Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:22Z DEBUG Failed to enable profile 'caTempTokenUserEncryptionKeyEnrollment' (it is probably already enabled) 2019-01-17T11:04:22Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 204 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=07BA34BF6BD7EB7053883F7321132495; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body '' 2019-01-17T11:04:22Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 200 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=4F343D8AE2E8FC6E559A372C3CAD0F3D; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:22Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:22Z DEBUG request body 'desc=This profile is for enrolling Token Signing key\nenable=true\nenableBy=admin\nname=Temporary Token User Signing Certificate Enrollment\nvisible=false\nauth.instance_id=AgentCertAuth\ninput.list=i1\ninput.i1.class_id=nsNKeyCertReqInputImpl\ninput.i1.name=nsNKeyCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=nsNKeyOutputImpl\noutput.o2.name=nsNKeyOutputImpl\npolicyset.list=set1\n#policyset.set1.list=p2,p4,p5,p1,p6,p7,p8,p9,p12,p13,p14\npolicyset.set1.list=p2,p4,p5,p1,p6,p8,p9,p12\npolicyset.set1.p1.constraint.class_id=noConstraintImpl\npolicyset.set1.p1.constraint.name=No Constraint\npolicyset.set1.p1.default.class_id=nsTokenUserKeySubjectNameDefaultImpl\npolicyset.set1.p1.default.name=nsTokenUserKeySubjectNameDefault\n#uncomment below to support SMIME\n#policyset.set1.p1.default.params.dnpattern=UID=$request.uid$, E=$request.mail$, O=Token Key User\npolicyset.set1.p1.default.params.dnpattern=UID=$request.uid$, O=Token Key User\n#changed ldap.enable to true to support SMIME\npolicyset.set1.p1.default.params.ldap.enable=false\npolicyset.set1.p1.default.params.ldap.searchName=uid\npolicyset.set1.p1.default.params.ldapStringAttributes=uid,mail\npolicyset.set1.p1.default.params.ldap.basedn=\npolicyset.set1.p1.default.params.ldap.maxConns=4\npolicyset.set1.p1.default.params.ldap.minConns=1\npolicyset.set1.p1.default.params.ldap.ldapconn.Version=2\npolicyset.set1.p1.default.params.ldap.ldapconn.host=\npolicyset.set1.p1.default.params.ldap.ldapconn.port=\npolicyset.set1.p1.default.params.ldap.ldapconn.secureConn=false\npolicyset.set1.p2.constraint.class_id=noConstraintImpl\npolicyset.set1.p2.constraint.name=No Constraint\npolicyset.set1.p2.default.class_id=validityDefaultImpl\npolicyset.set1.p2.default.name=Validity Default\npolicyset.set1.p2.default.params.range=7\npolicyset.set1.p2.default.params.startTime=0\npolicyset.set1.p4.constraint.class_id=noConstraintImpl\npolicyset.set1.p4.constraint.name=No Constraint\npolicyset.set1.p4.default.class_id=signingAlgDefaultImpl\npolicyset.set1.p4.default.name=Signing Algorithm Default\npolicyset.set1.p4.default.params.signingAlg=-\npolicyset.set1.p5.constraint.class_id=noConstraintImpl\npolicyset.set1.p5.constraint.name=No Constraint\npolicyset.set1.p5.default.class_id=keyUsageExtDefaultImpl\npolicyset.set1.p5.default.name=Key Usage Extension Default\npolicyset.set1.p5.default.params.keyUsageCritical=true\npolicyset.set1.p5.default.params.keyUsageCrlSign=false\npolicyset.set1.p5.default.params.keyUsageDataEncipherment=false\npolicyset.set1.p5.default.params.keyUsageDecipherOnly=false\npolicyset.set1.p5.default.params.keyUsageDigitalSignature=true\npolicyset.set1.p5.default.params.keyUsageEncipherOnly=false\npolicyset.set1.p5.default.params.keyUsageKeyAgreement=false\npolicyset.set1.p5.default.params.keyUsageKeyCertSign=false\npolicyset.set1.p5.default.params.keyUsageKeyEncipherment=false\npolicyset.set1.p5.default.params.keyUsageNonRepudiation=true\npolicyset.set1.p6.constraint.class_id=noConstraintImpl\npolicyset.set1.p6.constraint.name=No Constraint\npolicyset.set1.p6.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.set1.p6.default.name=Subject Alternative Name Extension Default\npolicyset.set1.p6.default.params.subjAltExtGNEnable_0=true\npolicyset.set1.p6.default.params.subjAltExtGNEnable_1=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_2=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_3=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_4=false\npolicyset.set1.p6.default.params.subjAltExtPattern_0=$request.mail$\npolicyset.set1.p6.default.params.subjAltExtPattern_1=\npolicyset.set1.p6.default.params.subjAltExtPattern_2=\npolicyset.set1.p6.default.params.subjAltExtPattern_3=\npolicyset.set1.p6.default.params.subjAltExtPattern_4=\npolicyset.set1.p6.default.params.subjAltExtType_0=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_1=OtherName\npolicyset.set1.p6.default.params.subjAltExtType_2=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_3=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_4=RFC822Name\npolicyset.set1.p6.default.params.subjAltNameExtCritical=false\npolicyset.set1.p6.default.params.subjAltNameNumGNs=1\npolicyset.set1.p7.constraint.class_id=noConstraintImpl\npolicyset.set1.p7.constraint.name=No Constraint\npolicyset.set1.p7.default.class_id=certificatePoliciesExtDefaultImpl\npolicyset.set1.p7.default.name=Certificate Policies Extension Default\npolicyset.set1.p7.default.params.Critical=false\npolicyset.set1.p7.default.params.PoliciesExt.num=5\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.CPSURI.enable=true\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p8.constraint.class_id=noConstraintImpl\npolicyset.set1.p8.constraint.name=No Constraint\npolicyset.set1.p8.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.set1.p8.default.name=Subject Key Identifier Default\npolicyset.set1.p9.constraint.class_id=noConstraintImpl\npolicyset.set1.p9.constraint.name=No Constraint\npolicyset.set1.p9.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.set1.p9.default.name=Authority Key Identifier Extension Default\npolicyset.set1.p12.constraint.class_id=basicConstraintsExtConstraintImpl\npolicyset.set1.p12.constraint.name=Basic Constraints Extension Constraint\npolicyset.set1.p12.constraint.params.basicConstraintsCritical=-\npolicyset.set1.p12.constraint.params.basicConstraintsIsCA=-\npolicyset.set1.p12.constraint.params.basicConstraintsMaxPathLen=-1\npolicyset.set1.p12.constraint.params.basicConstraintsMinPathLen=-1\npolicyset.set1.p12.default.class_id=basicConstraintsExtDefaultImpl\npolicyset.set1.p12.default.name=Basic Constraints Extension Default\npolicyset.set1.p12.default.params.basicConstraintsCritical=false\npolicyset.set1.p12.default.params.basicConstraintsIsCA=false\npolicyset.set1.p12.default.params.basicConstraintsPathLen=-1\npolicyset.set1.p13.constraint.class_id=noConstraintImpl\npolicyset.set1.p13.constraint.name=No Constraint\npolicyset.set1.p13.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.set1.p13.default.name=crlDistributionPointsExtDefaultImpl\npolicyset.set1.p13.default.params.crlDistPointsCritical=false\npolicyset.set1.p13.default.params.crlDistPointsNum=1\npolicyset.set1.p13.default.params.crlDistPointsEnable_0=false\npolicyset.set1.p13.default.params.crlDistPointsIssuerName_0=\npolicyset.set1.p13.default.params.crlDistPointsIssuerType_0=\npolicyset.set1.p13.default.params.crlDistPointsPointName_0=\npolicyset.set1.p13.default.params.crlDistPointsPointType_0=URIName\npolicyset.set1.p13.default.params.crlDistPointsReasons_0=\npolicyset.set1.p14.constraint.class_id=noConstraintImpl\npolicyset.set1.p14.constraint.name=No Constraint\npolicyset.set1.p14.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.set1.p14.default.name=AIA Extension Default\npolicyset.set1.p14.default.params.authInfoAccessADEnable_0=false\npolicyset.set1.p14.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.set1.p14.default.params.authInfoAccessADLocation_0=\npolicyset.set1.p14.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.set1.p14.default.params.authInfoAccessCritical=false\npolicyset.set1.p14.default.params.authInfoAccessNumADs=1\nprofileId=caTempTokenUserSigningKeyEnrollment\nclassId=caUserCertEnrollImpl\n' 2019-01-17T11:04:22Z DEBUG response status 409 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:22Z DEBUG Error migrating 'caTempTokenUserSigningKeyEnrollment': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:22Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caTempTokenUserSigningKeyEnrollment?action=enable 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 500 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:22 GMT Connection: close 2019-01-17T11:04:22Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:22Z DEBUG Failed to enable profile 'caTempTokenUserSigningKeyEnrollment' (it is probably already enabled) 2019-01-17T11:04:22Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 204 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=EADF62D46954C1538116560168E41B5E; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body '' 2019-01-17T11:04:22Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 200 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=8C2548D65A1EC5CA5426EDABEBC4FD36; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:22Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:22Z DEBUG request body 'desc=This certificate profile is for enrolling Security Domain administrator\'s certificates with LDAP authentication against the internal LDAP database.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=TokenAuth\nauthz.acl=group="Enterprise OCSP Administrators" || group="Enterprise RA Administrators" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators"\nname=Security Domain Administrator Certificate Enrollment\ninput.list=i1,i2,i3\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\ninput.i3.class_id=subjectDNInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=adminCertSet\npolicyset.adminCertSet.list=1,2,3,4,5,6,7,8\npolicyset.adminCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.adminCertSet.1.constraint.name=Subject Name Constraint\npolicyset.adminCertSet.1.constraint.params.pattern=.*\npolicyset.adminCertSet.1.constraint.params.accept=true\npolicyset.adminCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.adminCertSet.1.default.name=Subject Name Default\npolicyset.adminCertSet.1.default.params.name=\npolicyset.adminCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.adminCertSet.2.constraint.name=Validity Constraint\npolicyset.adminCertSet.2.constraint.params.range=365\npolicyset.adminCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.adminCertSet.2.constraint.params.notAfterCheck=false\npolicyset.adminCertSet.2.default.class_id=validityDefaultImpl\npolicyset.adminCertSet.2.default.name=Validity Default\npolicyset.adminCertSet.2.default.params.range=365\npolicyset.adminCertSet.2.default.params.startTime=0\npolicyset.adminCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.adminCertSet.3.constraint.name=Key Constraint\npolicyset.adminCertSet.3.constraint.params.keyType=RSA\npolicyset.adminCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.adminCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.adminCertSet.3.default.name=Key Default\npolicyset.adminCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.adminCertSet.4.constraint.name=No Constraint\npolicyset.adminCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.adminCertSet.4.default.name=Authority Key Identifier Default\npolicyset.adminCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.adminCertSet.5.constraint.name=No Constraint\npolicyset.adminCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.adminCertSet.5.default.name=AIA Extension Default\npolicyset.adminCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.adminCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.adminCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.adminCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.adminCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.adminCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.adminCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.adminCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.adminCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.adminCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.adminCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.adminCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.adminCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.adminCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.adminCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.adminCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.adminCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.adminCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.adminCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.adminCertSet.6.default.name=Key Usage Default\npolicyset.adminCertSet.6.default.params.keyUsageCritical=true\npolicyset.adminCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.adminCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.adminCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.adminCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.adminCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.adminCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.adminCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.adminCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.adminCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.adminCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.adminCertSet.7.constraint.name=No Constraint\npolicyset.adminCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.adminCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.adminCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.adminCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.adminCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.adminCertSet.8.constraint.name=No Constraint\npolicyset.adminCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.adminCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.adminCertSet.8.default.name=Signing Alg\npolicyset.adminCertSet.8.default.params.signingAlg=-\nprofileId=caAdminCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:22Z DEBUG response status 409 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:22Z DEBUG Error migrating 'caAdminCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:22Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caAdminCert?action=enable 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 500 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:22 GMT Connection: close 2019-01-17T11:04:22Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:22Z DEBUG Failed to enable profile 'caAdminCert' (it is probably already enabled) 2019-01-17T11:04:22Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 204 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=13F9012349C698D87A664CD49841648F; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body '' 2019-01-17T11:04:22Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 200 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=CE3A7D0B38ACAFB2C0C5D0274822461A; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:22Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:22Z DEBUG request body 'desc=This certificate profile is for enrolling Security Domain administrator\'s certificates with LDAP authentication against the internal LDAP database.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=TokenAuth\nauthz.acl=group="Enterprise OCSP Administrators" || group="Enterprise RA Administrators" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators"\nname=Security Domain Administrator Certificate Enrollment\ninput.list=i1,i2,i3\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\ninput.i3.class_id=subjectDNInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=adminCertSet\npolicyset.adminCertSet.list=1,2,3,4,5,6,7,8\npolicyset.adminCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.adminCertSet.1.constraint.name=Subject Name Constraint\npolicyset.adminCertSet.1.constraint.params.pattern=.*\npolicyset.adminCertSet.1.constraint.params.accept=true\npolicyset.adminCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.adminCertSet.1.default.name=Subject Name Default\npolicyset.adminCertSet.1.default.params.name=\npolicyset.adminCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.adminCertSet.2.constraint.name=Validity Constraint\npolicyset.adminCertSet.2.constraint.params.range=365\npolicyset.adminCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.adminCertSet.2.constraint.params.notAfterCheck=false\npolicyset.adminCertSet.2.default.class_id=validityDefaultImpl\npolicyset.adminCertSet.2.default.name=Validity Default\npolicyset.adminCertSet.2.default.params.range=365\npolicyset.adminCertSet.2.default.params.startTime=0\npolicyset.adminCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.adminCertSet.3.constraint.name=Key Constraint\npolicyset.adminCertSet.3.constraint.params.keyType=RSA\npolicyset.adminCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.adminCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.adminCertSet.3.default.name=Key Default\npolicyset.adminCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.adminCertSet.4.constraint.name=No Constraint\npolicyset.adminCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.adminCertSet.4.default.name=Authority Key Identifier Default\npolicyset.adminCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.adminCertSet.5.constraint.name=No Constraint\npolicyset.adminCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.adminCertSet.5.default.name=AIA Extension Default\npolicyset.adminCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.adminCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.adminCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.adminCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.adminCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.adminCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.adminCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.adminCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.adminCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.adminCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.adminCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.adminCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.adminCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.adminCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.adminCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.adminCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.adminCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.adminCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.adminCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.adminCertSet.6.default.name=Key Usage Default\npolicyset.adminCertSet.6.default.params.keyUsageCritical=true\npolicyset.adminCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.adminCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.adminCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.adminCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.adminCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.adminCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.adminCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.adminCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.adminCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.adminCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.adminCertSet.7.constraint.name=No Constraint\npolicyset.adminCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.adminCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.adminCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.adminCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.adminCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.adminCertSet.8.constraint.name=No Constraint\npolicyset.adminCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.adminCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.adminCertSet.8.default.name=Signing Alg\npolicyset.adminCertSet.8.default.params.signingAlg=-\nprofileId=caECAdminCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:22Z DEBUG response status 409 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:22Z DEBUG Error migrating 'caECAdminCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:22Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caECAdminCert?action=enable 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 500 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:22 GMT Connection: close 2019-01-17T11:04:22Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:22Z DEBUG Failed to enable profile 'caECAdminCert' (it is probably already enabled) 2019-01-17T11:04:22Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 204 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=78CC466829D735100AA29DA465F62608; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body '' 2019-01-17T11:04:22Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 200 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=5A06ACCD9A4982980830BB2BF22F76CE; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:22Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:22Z DEBUG request body 'desc=This certificate profile is for enrolling Security Domain server certificates.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=TokenAuth\nauthz.acl=group="Enterprise OCSP Administrators" || group="Enterprise RA Administrators" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators"\nname=Security Domain Server Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\ninput.i3.class_id=subjectAltNameExtInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,12\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=720\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=720\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\n# allows SAN to be specified from client side\n# need to:\n# 1. add i3 to input.list above\n# 2. add 9 to policyset.serverCertSet.list above\n# 3. change below to reflect the number of general names, and\n# turn each corresponding subjAltExtPattern_ to true\n# policyset.serverCertSet.9.default.params.subjAltNameNumGNs\n#\n# If the subjectAltNameExtDefaultImpl is on, then commonNameToSANDefault\n# would "merge" into existing SAN. Keep commonNameToSANDefault as last entry\n#\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.9.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.serverCertSet.9.default.name=Subject Alternative Name Extension Default\npolicyset.serverCertSet.9.default.params.subjAltExtGNEnable_0=true\npolicyset.serverCertSet.9.default.params.subjAltExtPattern_0=$request.req_san_pattern_0$\npolicyset.serverCertSet.9.default.params.subjAltExtType_0=DNSName\npolicyset.serverCertSet.9.default.params.subjAltExtGNEnable_1=false\npolicyset.serverCertSet.9.default.params.subjAltExtPattern_1=$request.req_san_pattern_1$\npolicyset.serverCertSet.9.default.params.subjAltExtType_1=DNSName\npolicyset.serverCertSet.9.default.params.subjAltExtGNEnable_2=false\npolicyset.serverCertSet.9.default.params.subjAltExtPattern_2=$request.req_san_pattern_2$\npolicyset.serverCertSet.9.default.params.subjAltExtType_2=DNSName\npolicyset.serverCertSet.9.default.params.subjAltNameExtCritical=false\npolicyset.serverCertSet.9.default.params.subjAltNameNumGNs=1\n#\n# While the subjectAltNameExtDefaultImpl above allows multiple SANs to be\n# specified during installation, the commonNameToSANDefaultImpl adds a simple\n# default single SAN from CN.\n#\n# If the subjectAltNameExtDefaultImpl is on, then commonNameToSANDefault\n# would "merge" into existing SAN. Keep commonNameToSANDefault as last entry\n#\npolicyset.serverCertSet.12.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.12.constraint.name=No Constraint\npolicyset.serverCertSet.12.default.class_id=commonNameToSANDefaultImpl\npolicyset.serverCertSet.12.default.name=Copy Common Name to Subject Alternative Name Extension\nprofileId=caInternalAuthServerCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:22Z DEBUG response status 409 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:22Z DEBUG Error migrating 'caInternalAuthServerCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:22Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caInternalAuthServerCert?action=enable 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 500 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:22 GMT Connection: close 2019-01-17T11:04:22Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:22Z DEBUG Failed to enable profile 'caInternalAuthServerCert' (it is probably already enabled) 2019-01-17T11:04:22Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 204 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=594EBE24B58C4162B4C978A6A3CEE362; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body '' 2019-01-17T11:04:22Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 200 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=DDE4F19B41124179626ED081614B63A7; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:22Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:22Z DEBUG request body 'desc=This certificate profile is for enrolling Security Domain ECC server certificates.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=TokenAuth\nauthz.acl=group="Enterprise OCSP Administrators" || group="Enterprise RA Administrators" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators"\nname=Security Domain Server Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\ninput.i3.class_id=subjectAltNameExtInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,12\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=720\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=720\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=-\npolicyset.serverCertSet.3.constraint.params.keyParameters=nistp256,nistp384,nistp521\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\n# allows SAN to be specified from client side\n# need to:\n# 1. add i3 to input.list above\n# 2. add 9 to policyset.serverCertSet.list above\n# 3. change below to reflect the number of general names, and\n# turn each corresponding subjAltExtPattern_ to true\n# policyset.serverCertSet.9.default.params.subjAltNameNumGNs\n#\n# If the subjectAltNameExtDefaultImpl is on, then commonNameToSANDefault\n# would "merge" into existing SAN. Keep commonNameToSANDefault as last entry\n#\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.9.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.serverCertSet.9.default.name=Subject Alternative Name Extension Default\npolicyset.serverCertSet.9.default.params.subjAltExtGNEnable_0=true\npolicyset.serverCertSet.9.default.params.subjAltExtPattern_0=$request.req_san_pattern_0$\npolicyset.serverCertSet.9.default.params.subjAltExtType_0=DNSName\npolicyset.serverCertSet.9.default.params.subjAltExtGNEnable_1=false\npolicyset.serverCertSet.9.default.params.subjAltExtPattern_1=$request.req_san_pattern_1$\npolicyset.serverCertSet.9.default.params.subjAltExtType_1=DNSName\npolicyset.serverCertSet.9.default.params.subjAltExtGNEnable_2=false\npolicyset.serverCertSet.9.default.params.subjAltExtPattern_2=$request.req_san_pattern_2$\npolicyset.serverCertSet.9.default.params.subjAltExtType_2=DNSName\npolicyset.serverCertSet.9.default.params.subjAltNameExtCritical=false\npolicyset.serverCertSet.9.default.params.subjAltNameNumGNs=1\n#\n# While the subjectAltNameExtDefaultImpl above allows multiple SANs to be\n# specified during installation, the commonNameToSANDefaultImpl adds a simple\n# default single SAN from CN.\n#\n# If the subjectAltNameExtDefaultImpl is on, then commonNameToSANDefault\n# would "merge" into existing SAN. Keep commonNameToSANDefault as last entry\n#\npolicyset.serverCertSet.12.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.12.constraint.name=No Constraint\npolicyset.serverCertSet.12.default.class_id=commonNameToSANDefaultImpl\npolicyset.serverCertSet.12.default.name=Copy Common Name to Subject Alternative Name Extension\nprofileId=caECInternalAuthServerCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:22Z DEBUG response status 409 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:22Z DEBUG Error migrating 'caECInternalAuthServerCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:22Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caECInternalAuthServerCert?action=enable 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 500 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:22 GMT Connection: close 2019-01-17T11:04:22Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:22Z DEBUG Failed to enable profile 'caECInternalAuthServerCert' (it is probably already enabled) 2019-01-17T11:04:22Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 204 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=991BA68BA22843C8307B16AB587F6887; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body '' 2019-01-17T11:04:22Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 200 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=F8EE3E764CFB6BBF23D0CCB46E263B42; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:22Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:22Z DEBUG request body 'desc=This certificate profile is for enrolling Security Domain Data Recovery Manager transport certificates.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=TokenAuth\nauthz.acl=group="Enterprise OCSP Administrators" || group="Enterprise RA Administrators" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators"\nname=Security Domain Data Recovery Manager Transport Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=transportCertSet\npolicyset.transportCertSet.list=1,2,3,4,5,6,7,8\npolicyset.transportCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.transportCertSet.1.constraint.name=Subject Name Constraint\npolicyset.transportCertSet.1.constraint.params.pattern=CN=.*\npolicyset.transportCertSet.1.constraint.params.accept=true\npolicyset.transportCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.transportCertSet.1.default.name=Subject Name Default\npolicyset.transportCertSet.1.default.params.name=\npolicyset.transportCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.transportCertSet.2.constraint.name=Validity Constraint\npolicyset.transportCertSet.2.constraint.params.range=720\npolicyset.transportCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.transportCertSet.2.constraint.params.notAfterCheck=false\npolicyset.transportCertSet.2.default.class_id=validityDefaultImpl\npolicyset.transportCertSet.2.default.name=Validity Default\npolicyset.transportCertSet.2.default.params.range=720\npolicyset.transportCertSet.2.default.params.startTime=0\npolicyset.transportCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.transportCertSet.3.constraint.name=Key Constraint\npolicyset.transportCertSet.3.constraint.params.keyType=-\npolicyset.transportCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.transportCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.transportCertSet.3.default.name=Key Default\npolicyset.transportCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.transportCertSet.4.constraint.name=No Constraint\npolicyset.transportCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.transportCertSet.4.default.name=Authority Key Identifier Default\npolicyset.transportCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.transportCertSet.5.constraint.name=No Constraint\npolicyset.transportCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.transportCertSet.5.default.name=AIA Extension Default\npolicyset.transportCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.transportCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.transportCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.transportCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.transportCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.transportCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.transportCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.transportCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.transportCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.transportCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.transportCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.transportCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.transportCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.transportCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.transportCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.transportCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.transportCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.transportCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.transportCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.transportCertSet.6.default.name=Key Usage Default\npolicyset.transportCertSet.6.default.params.keyUsageCritical=true\npolicyset.transportCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.transportCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.transportCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.transportCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.transportCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.transportCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.transportCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.transportCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.transportCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.transportCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.transportCertSet.7.constraint.name=No Constraint\npolicyset.transportCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.transportCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.transportCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.transportCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2\npolicyset.transportCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.transportCertSet.8.constraint.name=No Constraint\npolicyset.transportCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.transportCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.transportCertSet.8.default.name=Signing Alg\npolicyset.transportCertSet.8.default.params.signingAlg=-\nprofileId=caInternalAuthTransportCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:22Z DEBUG response status 409 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:22Z DEBUG Error migrating 'caInternalAuthTransportCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:22Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caInternalAuthTransportCert?action=enable 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 500 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:22 GMT Connection: close 2019-01-17T11:04:22Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:22Z DEBUG Failed to enable profile 'caInternalAuthTransportCert' (it is probably already enabled) 2019-01-17T11:04:22Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 204 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=E9EAD59F159E615F7DC55FF629B515CA; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body '' 2019-01-17T11:04:22Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 200 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=04BF664D23188E305231EED419594E0D; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:22Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:22Z DEBUG request body 'desc=This certificate profile is for enrolling Security Domain DRM storage certificates\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=TokenAuth\nauthz.acl=group="Enterprise OCSP Administrators" || group="Enterprise RA Administrators" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators"\nname=Security Domain DRM storage Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=drmStorageCertSet\npolicyset.drmStorageCertSet.list=1,2,3,4,5,6,7,9\npolicyset.drmStorageCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.drmStorageCertSet.1.constraint.name=Subject Name Constraint\npolicyset.drmStorageCertSet.1.constraint.params.pattern=CN=.*\npolicyset.drmStorageCertSet.1.constraint.params.accept=true\npolicyset.drmStorageCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.drmStorageCertSet.1.default.name=Subject Name Default\npolicyset.drmStorageCertSet.1.default.params.name=\npolicyset.drmStorageCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.drmStorageCertSet.2.constraint.name=Validity Constraint\npolicyset.drmStorageCertSet.2.constraint.params.range=720\npolicyset.drmStorageCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.drmStorageCertSet.2.constraint.params.notAfterCheck=false\npolicyset.drmStorageCertSet.2.default.class_id=validityDefaultImpl\npolicyset.drmStorageCertSet.2.default.name=Validity Default\npolicyset.drmStorageCertSet.2.default.params.range=720\npolicyset.drmStorageCertSet.2.default.params.startTime=0\npolicyset.drmStorageCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.drmStorageCertSet.3.constraint.name=Key Constraint\npolicyset.drmStorageCertSet.3.constraint.params.keyType=-\npolicyset.drmStorageCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.drmStorageCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.drmStorageCertSet.3.default.name=Key Default\npolicyset.drmStorageCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.drmStorageCertSet.4.constraint.name=No Constraint\npolicyset.drmStorageCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.drmStorageCertSet.4.default.name=Authority Key Identifier Default\npolicyset.drmStorageCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.drmStorageCertSet.5.constraint.name=No Constraint\npolicyset.drmStorageCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.drmStorageCertSet.5.default.name=AIA Extension Default\npolicyset.drmStorageCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.drmStorageCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.drmStorageCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.drmStorageCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.drmStorageCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.drmStorageCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.drmStorageCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.drmStorageCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.drmStorageCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.drmStorageCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.drmStorageCertSet.6.default.name=Key Usage Default\npolicyset.drmStorageCertSet.6.default.params.keyUsageCritical=true\npolicyset.drmStorageCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.drmStorageCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.drmStorageCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.drmStorageCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.drmStorageCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.drmStorageCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.drmStorageCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.drmStorageCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.drmStorageCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.drmStorageCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.drmStorageCertSet.7.constraint.name=No Constraint\npolicyset.drmStorageCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.drmStorageCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.drmStorageCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.drmStorageCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2\npolicyset.drmStorageCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.drmStorageCertSet.9.constraint.name=No Constraint\npolicyset.drmStorageCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.drmStorageCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.drmStorageCertSet.9.default.name=Signing Alg\npolicyset.drmStorageCertSet.9.default.params.signingAlg=-\nprofileId=caInternalAuthDRMstorageCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:22Z DEBUG response status 409 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:22Z DEBUG Error migrating 'caInternalAuthDRMstorageCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:22Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caInternalAuthDRMstorageCert?action=enable 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 500 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:22 GMT Connection: close 2019-01-17T11:04:22Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:22Z DEBUG Failed to enable profile 'caInternalAuthDRMstorageCert' (it is probably already enabled) 2019-01-17T11:04:22Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 204 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=1513FFDC333DF6193A5B1F7A1B79DA49; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body '' 2019-01-17T11:04:22Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 200 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=7CC702EE65D53414C594C53C59929B87; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:22Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:22Z DEBUG request body 'desc=This certificate profile is for enrolling Security Domain subsystem certificates.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=TokenAuth\nauthz.acl=group="Enterprise OCSP Administrators" || group="Enterprise RA Administrators" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators"\nname=Security Domain Subsystem Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\nupdater.list=u1\nupdater.u1.class_id=subsystemGroupUpdaterImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=720\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=720\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\nprofileId=caInternalAuthSubsystemCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:22Z DEBUG response status 409 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:22Z DEBUG Error migrating 'caInternalAuthSubsystemCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:22Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caInternalAuthSubsystemCert?action=enable 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 500 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:22 GMT Connection: close 2019-01-17T11:04:22Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:22Z DEBUG Failed to enable profile 'caInternalAuthSubsystemCert' (it is probably already enabled) 2019-01-17T11:04:22Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 204 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=C5C1131D7814CDC50CE8A77B4864DD03; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body '' 2019-01-17T11:04:22Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 200 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=421DAA4F39692BA7A4BBBEA083B7807F; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:22Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:22Z DEBUG request body 'desc=This certificate profile is for enrolling Security Domain subsystem certificates with ECC keys.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=TokenAuth\nauthz.acl=group="Enterprise OCSP Administrators" || group="Enterprise RA Administrators" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators"\nname=Security Domain Subsystem Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\nupdater.list=u1\nupdater.u1.class_id=subsystemGroupUpdaterImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=720\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=720\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=-\npolicyset.serverCertSet.3.constraint.params.keyParameters=nistp256,nistp384,nistp521\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=false\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA256withRSA,SHA512withRSA,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\nprofileId=caECInternalAuthSubsystemCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:22Z DEBUG response status 409 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:22Z DEBUG Error migrating 'caECInternalAuthSubsystemCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:22Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caECInternalAuthSubsystemCert?action=enable 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 500 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:22 GMT Connection: close 2019-01-17T11:04:22Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:22Z DEBUG Failed to enable profile 'caECInternalAuthSubsystemCert' (it is probably already enabled) 2019-01-17T11:04:22Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 204 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=BA363ACFDF9421BF8319680C8EC005D3; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body '' 2019-01-17T11:04:22Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 200 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=03A9BA96A93AC88ACB1DC7C69FDD0411; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:22Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:22Z DEBUG request body 'desc=This certificate profile is for enrolling Security Domain OCSP Manager certificates.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=TokenAuth\nauthz.acl=group="Enterprise OCSP Administrators" || group="Enterprise RA Administrators" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators"\nname=Security Domain OCSP Manager Signing Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=ocspCertSet\npolicyset.ocspCertSet.list=1,2,3,4,5,6,8,9\npolicyset.ocspCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.ocspCertSet.1.constraint.name=Subject Name Constraint\npolicyset.ocspCertSet.1.constraint.params.pattern=CN=.*\npolicyset.ocspCertSet.1.constraint.params.accept=true\npolicyset.ocspCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.ocspCertSet.1.default.name=Subject Name Default\npolicyset.ocspCertSet.1.default.params.name=\npolicyset.ocspCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.ocspCertSet.2.constraint.name=Validity Constraint\npolicyset.ocspCertSet.2.constraint.params.range=720\npolicyset.ocspCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.ocspCertSet.2.constraint.params.notAfterCheck=false\npolicyset.ocspCertSet.2.default.class_id=validityDefaultImpl\npolicyset.ocspCertSet.2.default.name=Validity Default\npolicyset.ocspCertSet.2.default.params.range=720\npolicyset.ocspCertSet.2.default.params.startTime=0\npolicyset.ocspCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.ocspCertSet.3.constraint.name=Key Constraint\npolicyset.ocspCertSet.3.constraint.params.keyType=-\npolicyset.ocspCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,nistp256,nistp384,nistp521\npolicyset.ocspCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.ocspCertSet.3.default.name=Key Default\npolicyset.ocspCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.ocspCertSet.4.constraint.name=No Constraint\npolicyset.ocspCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.ocspCertSet.4.default.name=Authority Key Identifier Default\npolicyset.ocspCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.ocspCertSet.5.constraint.name=No Constraint\npolicyset.ocspCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.ocspCertSet.5.default.name=AIA Extension Default\npolicyset.ocspCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.ocspCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.ocspCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.ocspCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.ocspCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.ocspCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.ocspCertSet.6.constraint.class_id=extendedKeyUsageExtConstraintImpl\npolicyset.ocspCertSet.6.constraint.name=Extended Key Usage Extension\npolicyset.ocspCertSet.6.constraint.params.exKeyUsageCritical=false\npolicyset.ocspCertSet.6.constraint.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.9\npolicyset.ocspCertSet.6.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.ocspCertSet.6.default.name=Extended Key Usage Default\npolicyset.ocspCertSet.6.default.params.exKeyUsageCritical=false\npolicyset.ocspCertSet.6.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.9\npolicyset.ocspCertSet.8.constraint.class_id=extensionConstraintImpl\npolicyset.ocspCertSet.8.constraint.name=No Constraint\npolicyset.ocspCertSet.8.constraint.params.extCritical=false\npolicyset.ocspCertSet.8.constraint.params.extOID=1.3.6.1.5.5.7.48.1.5\npolicyset.ocspCertSet.8.default.class_id=ocspNoCheckExtDefaultImpl\npolicyset.ocspCertSet.8.default.name=OCSP No Check Extension\npolicyset.ocspCertSet.8.default.params.ocspNoCheckCritical=false\npolicyset.ocspCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.ocspCertSet.9.constraint.name=No Constraint\npolicyset.ocspCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.ocspCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.ocspCertSet.9.default.name=Signing Alg\npolicyset.ocspCertSet.9.default.params.signingAlg=-\nprofileId=caInternalAuthOCSPCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:22Z DEBUG response status 409 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:22Z DEBUG Error migrating 'caInternalAuthOCSPCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:22Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caInternalAuthOCSPCert?action=enable 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 500 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:22 GMT Connection: close 2019-01-17T11:04:22Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:22Z DEBUG Failed to enable profile 'caInternalAuthOCSPCert' (it is probably already enabled) 2019-01-17T11:04:22Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 204 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=A18D8760C034415CE43333F90479D91D; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body '' 2019-01-17T11:04:22Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 200 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=6947FAC1F774A6DF7572ADCF3038CE38; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:22Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:22Z DEBUG request body 'desc=This certificate profile is for enrolling audit signing certificates.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=TokenAuth\nauthz.acl=group="Enterprise OCSP Administrators" || group="Enterprise RA Administrators" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators"\nname=Audit Signing Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=auditSigningCertSet\npolicyset.auditSigningCertSet.list=1,2,3,4,5,6,9\npolicyset.auditSigningCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.auditSigningCertSet.1.constraint.name=Subject Name Constraint\npolicyset.auditSigningCertSet.1.constraint.params.pattern=CN=.*\npolicyset.auditSigningCertSet.1.constraint.params.accept=true\npolicyset.auditSigningCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.auditSigningCertSet.1.default.name=Subject Name Default\npolicyset.auditSigningCertSet.1.default.params.name=\npolicyset.auditSigningCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.auditSigningCertSet.2.constraint.name=Validity Constraint\npolicyset.auditSigningCertSet.2.constraint.params.range=720\npolicyset.auditSigningCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.auditSigningCertSet.2.constraint.params.notAfterCheck=false\npolicyset.auditSigningCertSet.2.default.class_id=validityDefaultImpl\npolicyset.auditSigningCertSet.2.default.name=Validity Default\npolicyset.auditSigningCertSet.2.default.params.range=720\npolicyset.auditSigningCertSet.2.default.params.startTime=0\npolicyset.auditSigningCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.auditSigningCertSet.3.constraint.name=Key Constraint\npolicyset.auditSigningCertSet.3.constraint.params.keyType=-\npolicyset.auditSigningCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,nistp256,nistp521\npolicyset.auditSigningCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.auditSigningCertSet.3.default.name=Key Default\npolicyset.auditSigningCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.auditSigningCertSet.4.constraint.name=No Constraint\npolicyset.auditSigningCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.auditSigningCertSet.4.default.name=Authority Key Identifier Default\npolicyset.auditSigningCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.auditSigningCertSet.5.constraint.name=No Constraint\npolicyset.auditSigningCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.auditSigningCertSet.5.default.name=AIA Extension Default\npolicyset.auditSigningCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.auditSigningCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.auditSigningCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.auditSigningCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.auditSigningCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.auditSigningCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.auditSigningCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.auditSigningCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageKeyEncipherment=false\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.auditSigningCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.auditSigningCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.auditSigningCertSet.6.default.name=Key Usage Default\npolicyset.auditSigningCertSet.6.default.params.keyUsageCritical=true\npolicyset.auditSigningCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.auditSigningCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.auditSigningCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.auditSigningCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.auditSigningCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.auditSigningCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.auditSigningCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.auditSigningCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.auditSigningCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.auditSigningCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.auditSigningCertSet.9.constraint.name=No Constraint\npolicyset.auditSigningCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.auditSigningCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.auditSigningCertSet.9.default.name=Signing Alg\npolicyset.auditSigningCertSet.9.default.params.signingAlg=-\nprofileId=caInternalAuthAuditSigningCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:22Z DEBUG response status 409 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:22Z DEBUG Error migrating 'caInternalAuthAuditSigningCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:22Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caInternalAuthAuditSigningCert?action=enable 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 500 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:22 GMT Connection: close 2019-01-17T11:04:22Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:22Z DEBUG Failed to enable profile 'caInternalAuthAuditSigningCert' (it is probably already enabled) 2019-01-17T11:04:22Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 204 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=6A588D920BA546A95BA343AFACD5862E; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body '' 2019-01-17T11:04:22Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 200 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=4006EAF5EF3A252B2A77E0A76B971841; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:22Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:22Z DEBUG request body "desc=This profile is for enrolling Domain Controller Certificate\nenable=true\nenableBy=admin\nname=Domain Controller\nvisible=true\nauth.instance_id=AgentCertAuth\ninput.list=i1,i2,i3\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\ninput.i3.class_id=genericInputImpl\ninput.i3.params.gi_display_name0=ccm\ninput.i3.params.gi_param_enable0=true\ninput.i3.params.gi_param_name0=ccm\ninput.i3.params.gi_display_name1=GUID\ninput.i3.params.gi_param_enable1=true\ninput.i3.params.gi_param_name1=GUID\ninput.i3.params.gi_num=2\noutput.list=o1,o2\noutput.o1.class_id=certOutputImpl\noutput.o2.class_id=pkcs7OutputImpl\npolicyset.list=set1\npolicyset.set1.list=p2,p4,p5,subj,p6,p8,p9,p12,eku,gen,crldp\npolicyset.set1.subj.constraint.class_id=noConstraintImpl\npolicyset.set1.subj.constraint.name=No Constraint\npolicyset.set1.subj.default.class_id=nsTokenUserKeySubjectNameDefaultImpl\npolicyset.set1.subj.default.name=nsTokenUserKeySubjectNameDefault\n#policyset.set1.p1.default.params.dnpattern=UID=$request.uid$, E=$request.mail$, O=Token Key User\n#policyset.set1.subj.default.params.dnpattern=CN=GEMSTAR,OU=Domain Controllers,DC=test,dc=local\npolicyset.set1.subj.default.params.dnpattern=CN=$request.ccm$\npolicyset.set1.subj.default.params.ldap.enable=false\npolicyset.set1.subj.default.params.ldap.searchName=uid\npolicyset.set1.subj.default.params.ldapStringAttributes=uid,mail\npolicyset.set1.subj.default.params.ldap.basedn=\npolicyset.set1.subj.default.params.ldap.maxConns=4\npolicyset.set1.subj.default.params.ldap.minConns=1\npolicyset.set1.subj.default.params.ldap.ldapconn.Version=2\npolicyset.set1.subj.default.params.ldap.ldapconn.host=\npolicyset.set1.subj.default.params.ldap.ldapconn.port=\npolicyset.set1.subj.default.params.ldap.ldapconn.secureConn=false\npolicyset.set1.p2.constraint.class_id=noConstraintImpl\npolicyset.set1.p2.constraint.name=No Constraint\npolicyset.set1.p2.default.class_id=validityDefaultImpl\npolicyset.set1.p2.default.name=Validity Default\npolicyset.set1.p2.default.params.range=1825\npolicyset.set1.p2.default.params.startTime=0\npolicyset.set1.p4.constraint.class_id=noConstraintImpl\npolicyset.set1.p4.constraint.name=No Constraint\npolicyset.set1.p4.default.class_id=signingAlgDefaultImpl\npolicyset.set1.p4.default.name=Signing Algorithm Default\npolicyset.set1.p4.default.params.signingAlg=-\npolicyset.set1.p5.constraint.class_id=noConstraintImpl\npolicyset.set1.p5.constraint.name=No Constraint\npolicyset.set1.p5.default.class_id=keyUsageExtDefaultImpl\npolicyset.set1.p5.default.name=Key Usage Extension Default\npolicyset.set1.p5.default.params.keyUsageCritical=true\npolicyset.set1.p5.default.params.keyUsageCrlSign=false\npolicyset.set1.p5.default.params.keyUsageDataEncipherment=false\npolicyset.set1.p5.default.params.keyUsageDecipherOnly=false\npolicyset.set1.p5.default.params.keyUsageDigitalSignature=true\npolicyset.set1.p5.default.params.keyUsageEncipherOnly=false\npolicyset.set1.p5.default.params.keyUsageKeyAgreement=false\npolicyset.set1.p5.default.params.keyUsageKeyCertSign=false\npolicyset.set1.p5.default.params.keyUsageKeyEncipherment=true\npolicyset.set1.p5.default.params.keyUsageNonRepudiation=false\npolicyset.set1.p6.constraint.class_id=noConstraintImpl\npolicyset.set1.p6.constraint.name=No Constraint\npolicyset.set1.p6.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.set1.p6.default.name=Subject Alternative Name Extension Default\npolicyset.set1.p6.default.params.subjAltExtGNEnable_0=true\npolicyset.set1.p6.default.params.subjAltExtGNEnable_1=true\npolicyset.set1.p6.default.params.subjAltExtPattern_0=$request.ccm$\npolicyset.set1.p6.default.params.subjAltExtType_0=DNSName\npolicyset.set1.p6.default.params.subjAltExtPattern_1=(Any)1.3.6.1.4.1.311.25.1,0410$request.GUID$\npolicyset.set1.p6.default.params.subjAltExtType_1=OtherName\npolicyset.set1.p6.default.params.subjAltNameExtCritical=false\npolicyset.set1.p6.default.params.subjAltNameNumGNs=2\npolicyset.set1.5.constraint.class_id=noConstraintImpl\npolicyset.set1.5.constraint.name=No Constraint\npolicyset.set1.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.set1.5.default.name=AIA Extension Default\npolicyset.set1.5.default.params.authInfoAccessADEnable_0=true\npolicyset.set1.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.set1.5.default.params.authInfoAccessADLocation_0=http://localhost.localdomain:9180/ca/ee/ca/getCRL?crlIssuingPoint=MasterCRL&op=getCRL&crlDisplayType=cachedCRL&submit=Submit\npolicyset.set1.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.2\npolicyset.set1.5.default.params.authInfoAccessCritical=false\npolicyset.set1.5.default.params.authInfoAccessNumADs=1\npolicyset.set1.eku.constraint.class_id=noConstraintImpl\npolicyset.set1.eku.constraint.name=No Constraint\npolicyset.set1.eku.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.set1.eku.default.name=Extended Key Usage Extension Default\npolicyset.set1.eku.default.params.exKeyUsageCritical=false\npolicyset.set1.eku.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2\npolicyset.set1.p8.constraint.class_id=noConstraintImpl\npolicyset.set1.p8.constraint.name=No Constraint\npolicyset.set1.p8.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.set1.p8.default.name=Subject Key Identifier Default\npolicyset.set1.p9.constraint.class_id=noConstraintImpl\npolicyset.set1.p9.constraint.name=No Constraint\npolicyset.set1.p9.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.set1.p9.default.name=Authority Key Identifier Extension Default\npolicyset.set1.p12.constraint.class_id=basicConstraintsExtConstraintImpl\npolicyset.set1.p12.constraint.name=Basic Constraints Extension Constraint\npolicyset.set1.p12.constraint.params.basicConstraintsCritical=-\npolicyset.set1.p12.constraint.params.basicConstraintsIsCA=-\npolicyset.set1.p12.constraint.params.basicConstraintsMaxPathLen=-1\npolicyset.set1.p12.constraint.params.basicConstraintsMinPathLen=-1\npolicyset.set1.p12.default.class_id=basicConstraintsExtDefaultImpl\npolicyset.set1.p12.default.name=Basic Constraints Extension Default\npolicyset.set1.p12.default.params.basicConstraintsCritical=false\npolicyset.set1.p12.default.params.basicConstraintsIsCA=false\npolicyset.set1.p12.default.params.basicConstraintsPathLen=-1\npolicyset.set1.crldp.constraint.class_id=noConstraintImpl\npolicyset.set1.crldp.constraint.name=No Constraint\npolicyset.set1.crldp.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.set1.crldp.default.name=crlDistributionPointsExtDefaultImpl\npolicyset.set1.crldp.default.params.crlDistPointsCritical=false\npolicyset.set1.crldp.default.params.crlDistPointsNum=1\npolicyset.set1.crldp.default.params.crlDistPointsEnable_0=true\npolicyset.set1.crldp.default.params.crlDistPointsIssuerName_0=\npolicyset.set1.crldp.default.params.crlDistPointsIssuerType_0=\npolicyset.set1.crldp.default.params.crlDistPointsPointName_0=http://localhost.localdomain:9180/ca/ee/ca/getCRL?crlIssuingPoint=MasterCRL&op=getCRL&crlDisplayType=cachedCRL&submit=Submit\npolicyset.set1.crldp.default.params.crlDistPointsPointType_0=URIName\npolicyset.set1.crldp.default.params.crlDistPointsReasons_0=\npolicyset.set1.gen.constraint.class_id=noConstraintImpl\npolicyset.set1.gen.constraint.name=No Constraint\npolicyset.set1.gen.default.class_id=genericExtDefaultImpl\npolicyset.set1.gen.default.name=Generic Extension\n#This is the Microsoft 'Certificate Template Name' Extensions. The Value is 'DomainController'\npolicyset.set1.gen.default.params.genericExtOID=1.3.6.1.4.1.311.20.2\npolicyset.set1.gen.default.params.genericExtData=1e200044006f006d00610069006e0043006f006e00740072006f006c006c00650072\nprofileId=DomainController\nclassId=caEnrollImpl\n" 2019-01-17T11:04:22Z DEBUG response status 409 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:22Z DEBUG Error migrating 'DomainController': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:22Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/DomainController?action=enable 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 500 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:22 GMT Connection: close 2019-01-17T11:04:22Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:22Z DEBUG Failed to enable profile 'DomainController' (it is probably already enabled) 2019-01-17T11:04:22Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 204 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=38EF2827E8B23E78E7D212478D0C7151; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body '' 2019-01-17T11:04:22Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 200 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=220C5AF75C96AC08D9214BC3FD1AB444; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:22Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:22Z DEBUG request body 'desc=This certificate profile is for enrolling user certificates with RA agent authentication.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=raCertAuth\nname=RA Agent-Authenticated User Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=userCertSet\npolicyset.userCertSet.list=1,2,3,4,5,6,7,8,9\npolicyset.userCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.userCertSet.1.constraint.name=Subject Name Constraint\npolicyset.userCertSet.1.constraint.params.pattern=.*UID=.*\npolicyset.userCertSet.1.constraint.params.accept=true\npolicyset.userCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.userCertSet.1.default.name=Subject Name Default\npolicyset.userCertSet.1.default.params.name=\npolicyset.userCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.userCertSet.2.constraint.name=Validity Constraint\npolicyset.userCertSet.2.constraint.params.range=365\npolicyset.userCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.userCertSet.2.constraint.params.notAfterCheck=false\npolicyset.userCertSet.2.default.class_id=validityDefaultImpl\npolicyset.userCertSet.2.default.name=Validity Default\npolicyset.userCertSet.2.default.params.range=180\npolicyset.userCertSet.2.default.params.startTime=0\npolicyset.userCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.userCertSet.3.constraint.name=Key Constraint\npolicyset.userCertSet.3.constraint.params.keyType=RSA\npolicyset.userCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.userCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.userCertSet.3.default.name=Key Default\npolicyset.userCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.4.constraint.name=No Constraint\npolicyset.userCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.userCertSet.4.default.name=Authority Key Identifier Default\npolicyset.userCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.5.constraint.name=No Constraint\npolicyset.userCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.userCertSet.5.default.name=AIA Extension Default\npolicyset.userCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.userCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.userCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.userCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.userCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.userCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.userCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.userCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.userCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.userCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.userCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.userCertSet.6.default.name=Key Usage Default\npolicyset.userCertSet.6.default.params.keyUsageCritical=true\npolicyset.userCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.userCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.userCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.userCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.7.constraint.name=No Constraint\npolicyset.userCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.userCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.userCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.userCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.userCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.8.constraint.name=No Constraint\npolicyset.userCertSet.8.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.userCertSet.8.default.name=Subject Alt Name Constraint\npolicyset.userCertSet.8.default.params.subjAltNameExtCritical=false\npolicyset.userCertSet.8.default.params.subjAltExtType_0=RFC822Name\npolicyset.userCertSet.8.default.params.subjAltExtPattern_0=$request.requestor_email$\npolicyset.userCertSet.8.default.params.subjAltExtGNEnable_0=true\npolicyset.userCertSet.8.default.params.subjAltNameNumGNs=1\npolicyset.userCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.userCertSet.9.constraint.name=No Constraint\npolicyset.userCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.userCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.userCertSet.9.default.name=Signing Alg\npolicyset.userCertSet.9.default.params.signingAlg=-\nprofileId=caDualRAuserCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:22Z DEBUG response status 409 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:22Z DEBUG Error migrating 'caDualRAuserCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:22Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caDualRAuserCert?action=enable 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 500 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:22 GMT Connection: close 2019-01-17T11:04:22Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:22Z DEBUG Failed to enable profile 'caDualRAuserCert' (it is probably already enabled) 2019-01-17T11:04:22Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 204 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=7CD7DACE046207640592C0131FBD5C38; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body '' 2019-01-17T11:04:22Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 200 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=4C09297D1C796D0DF46E5DA67808BA30; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:22Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:22Z DEBUG request body 'desc=This certificate profile is for enrolling RA agent user certificates with RA agent authentication.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=raCertAuth\nname=RA Agent-Authenticated Agent User Certificate Enrollment\ninput.list=i1,i2,i3\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\ninput.i3.class_id=subjectDNInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=userCertSet\npolicyset.userCertSet.list=1,2,3,4,5,6,7,8,9\npolicyset.userCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.userCertSet.1.constraint.name=Subject Name Constraint\npolicyset.userCertSet.1.constraint.params.pattern=UID=.*\npolicyset.userCertSet.1.constraint.params.accept=true\npolicyset.userCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.userCertSet.1.default.name=Subject Name Default\npolicyset.userCertSet.1.default.params.name=\npolicyset.userCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.userCertSet.2.constraint.name=Validity Constraint\npolicyset.userCertSet.2.constraint.params.range=365\npolicyset.userCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.userCertSet.2.constraint.params.notAfterCheck=false\npolicyset.userCertSet.2.default.class_id=validityDefaultImpl\npolicyset.userCertSet.2.default.name=Validity Default\npolicyset.userCertSet.2.default.params.range=180\npolicyset.userCertSet.2.default.params.startTime=0\npolicyset.userCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.userCertSet.3.constraint.name=Key Constraint\npolicyset.userCertSet.3.constraint.params.keyType=RSA\npolicyset.userCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.userCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.userCertSet.3.default.name=Key Default\npolicyset.userCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.4.constraint.name=No Constraint\npolicyset.userCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.userCertSet.4.default.name=Authority Key Identifier Default\npolicyset.userCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.5.constraint.name=No Constraint\npolicyset.userCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.userCertSet.5.default.name=AIA Extension Default\npolicyset.userCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.userCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.userCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.userCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.userCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.userCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.userCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.userCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.userCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.userCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.userCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.userCertSet.6.default.name=Key Usage Default\npolicyset.userCertSet.6.default.params.keyUsageCritical=true\npolicyset.userCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.userCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.userCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.userCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.7.constraint.name=No Constraint\npolicyset.userCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.userCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.userCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.userCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.userCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.8.constraint.name=No Constraint\npolicyset.userCertSet.8.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.userCertSet.8.default.name=Subject Alt Name Constraint\npolicyset.userCertSet.8.default.params.subjAltNameExtCritical=false\npolicyset.userCertSet.8.default.params.subjAltExtType_0=RFC822Name\npolicyset.userCertSet.8.default.params.subjAltExtPattern_0=$request.requestor_email$\npolicyset.userCertSet.8.default.params.subjAltExtGNEnable_0=true\npolicyset.userCertSet.8.default.params.subjAltNameNumGNs=1\npolicyset.userCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.userCertSet.9.constraint.name=No Constraint\npolicyset.userCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.userCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.userCertSet.9.default.name=Signing Alg\npolicyset.userCertSet.9.default.params.signingAlg=-\nprofileId=caRAagentCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:22Z DEBUG response status 409 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:22Z DEBUG Error migrating 'caRAagentCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:22Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caRAagentCert?action=enable 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 500 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:22 GMT Connection: close 2019-01-17T11:04:22Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:22Z DEBUG Failed to enable profile 'caRAagentCert' (it is probably already enabled) 2019-01-17T11:04:22Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 204 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=84C54FA34F2A8E2C1722282951AE85B6; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body '' 2019-01-17T11:04:22Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:22Z DEBUG response status 200 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=8C73FE70205801A4F7D242DA33EB0FEB; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:22Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:22Z DEBUG request body 'desc=This certificate profile is for enrolling server certificates with RA agent authentication.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=raCertAuth\nname=RA Agent-Authenticated Server Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=.*\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=365\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=180\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\nprofileId=caRAserverCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:22Z DEBUG response status 409 2019-01-17T11:04:22Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:22Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:22Z DEBUG Error migrating 'caRAserverCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:22Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caRAserverCert?action=enable 2019-01-17T11:04:22Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 500 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:22 GMT Connection: close 2019-01-17T11:04:23Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:23Z DEBUG Failed to enable profile 'caRAserverCert' (it is probably already enabled) 2019-01-17T11:04:23Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 204 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=CA899858DB5B89D30FB8CEB169AB0398; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:22 GMT 2019-01-17T11:04:23Z DEBUG response body '' 2019-01-17T11:04:23Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 200 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=C50543EF263E9C49970A26A69EA8DE42; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:23Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:23Z DEBUG request body 'desc=This certificate profile is for enrolling device certificates to contain UUID in the Subject Alternative Name extension\nvisible=true\nenable=false\nenableBy=admin\nname=Manual device Dual-Use Certificate Enrollment to contain UUID in SAN\nauth.class_id=\ninput.list=i1,i2,i3\ninput.i1.class_id=keyGenInputImpl\ninput.i2.class_id=subjectNameInputImpl\ninput.i3.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=userCertSet\npolicyset.userCertSet.list=1,2,3,4,5,6,7,8,9\npolicyset.userCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.userCertSet.1.constraint.name=Subject Name Constraint\npolicyset.userCertSet.1.constraint.params.pattern=UID=.*\npolicyset.userCertSet.1.constraint.params.accept=true\npolicyset.userCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.userCertSet.1.default.name=Subject Name Default\npolicyset.userCertSet.1.default.params.name=\npolicyset.userCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.userCertSet.2.constraint.name=Validity Constraint\npolicyset.userCertSet.2.constraint.params.range=365\npolicyset.userCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.userCertSet.2.constraint.params.notAfterCheck=false\npolicyset.userCertSet.2.default.class_id=validityDefaultImpl\npolicyset.userCertSet.2.default.name=Validity Default\npolicyset.userCertSet.2.default.params.range=180\npolicyset.userCertSet.2.default.params.startTime=0\npolicyset.userCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.userCertSet.3.constraint.name=Key Constraint\npolicyset.userCertSet.3.constraint.params.keyType=-\npolicyset.userCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,nistp256,nistp384,nistp521\npolicyset.userCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.userCertSet.3.default.name=Key Default\npolicyset.userCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.4.constraint.name=No Constraint\npolicyset.userCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.userCertSet.4.default.name=Authority Key Identifier Default\npolicyset.userCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.5.constraint.name=No Constraint\npolicyset.userCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.userCertSet.5.default.name=AIA Extension Default\npolicyset.userCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.userCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.userCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.userCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.userCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.userCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.userCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.userCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.userCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.userCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.userCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.userCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.userCertSet.6.default.name=Key Usage Default\npolicyset.userCertSet.6.default.params.keyUsageCritical=true\npolicyset.userCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.userCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.userCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.userCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.userCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.userCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.userCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.userCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.userCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.userCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.7.constraint.name=No Constraint\npolicyset.userCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.userCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.userCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.userCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.userCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.userCertSet.8.constraint.name=No Constraint\npolicyset.userCertSet.8.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.userCertSet.8.default.name=Subject Alt Name Constraint\npolicyset.userCertSet.8.default.params.subjAltNameExtCritical=false\npolicyset.userCertSet.8.default.params.subjAltExtType_0=RFC822Name\npolicyset.userCertSet.8.default.params.subjAltExtPattern_0=$request.requestor_email$\npolicyset.userCertSet.8.default.params.subjAltExtGNEnable_0=true\npolicyset.userCertSet.8.default.params.subjAltExtType_1=OtherName\npolicyset.userCertSet.8.default.params.subjAltExtPattern_1=(IA5String)1.2.3.4,$server.source$\npolicyset.userCertSet.8.default.params.subjAltExtGNEnable_1=true\npolicyset.userCertSet.8.default.params.subjAltExtSource_1=UUID4\npolicyset.userCertSet.8.default.params.subjAltNameNumGNs=2\npolicyset.userCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.userCertSet.9.constraint.name=No Constraint\npolicyset.userCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.userCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.userCertSet.9.default.name=Signing Alg\npolicyset.userCertSet.9.default.params.signingAlg=-\nprofileId=caUUIDdeviceCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:23Z DEBUG response status 409 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:23Z DEBUG Error migrating 'caUUIDdeviceCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:23Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caUUIDdeviceCert?action=enable 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 500 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:23 GMT Connection: close 2019-01-17T11:04:23Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:23Z DEBUG Failed to enable profile 'caUUIDdeviceCert' (it is probably already enabled) 2019-01-17T11:04:23Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 204 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=5CFC3690E249DB172733375BF52F2D70; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body '' 2019-01-17T11:04:23Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 200 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=18A5B85314ED6211780B4004FE96C999; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:23Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:23Z DEBUG request body 'desc=This certificate profile is for renewing SSL client certificates.\nvisible=true\nenable=true\nenableBy=admin\nrenewal=true\nauth.instance_id=SSLclientCertAuth\nname=Renewal: Self-renew user SSL client certificates\noutput.list=o1\noutput.o1.class_id=certOutputImpl\nprofileId=caSSLClientSelfRenewal\nclassId=caEnrollImpl\n' 2019-01-17T11:04:23Z DEBUG response status 409 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:23Z DEBUG Error migrating 'caSSLClientSelfRenewal': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:23Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caSSLClientSelfRenewal?action=enable 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 500 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:23 GMT Connection: close 2019-01-17T11:04:23Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:23Z DEBUG Failed to enable profile 'caSSLClientSelfRenewal' (it is probably already enabled) 2019-01-17T11:04:23Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 204 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=944BBB82FAFFE5CABD974DF2FCED43EE; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body '' 2019-01-17T11:04:23Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 200 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=EA7C3284B2E9EAD181BD1F3C5936DE2A; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:23Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:23Z DEBUG request body 'desc=This certificate profile is for renewing a certificate by serial number by using directory based authentication.\nvisible=true\nenable=true\nenableBy=admin\nrenewal=true\nauth.instance_id=UserDirEnrollment\nauthz.acl=user_origreq="auth_token.uid"\nname=Renewal: Directory-Authenticated User Certificate Self-Renew profile\ninput.list=i1\ninput.i1.class_id=serialNumRenewInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\nprofileId=caDirUserRenewal\nclassId=caEnrollImpl\n' 2019-01-17T11:04:23Z DEBUG response status 409 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:23Z DEBUG Error migrating 'caDirUserRenewal': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:23Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caDirUserRenewal?action=enable 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 500 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:23 GMT Connection: close 2019-01-17T11:04:23Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:23Z DEBUG Failed to enable profile 'caDirUserRenewal' (it is probably already enabled) 2019-01-17T11:04:23Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 204 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=1F7B6EF51165DADA8F5B03C04244C37D; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body '' 2019-01-17T11:04:23Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 200 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=536B0F245EB209F0FA089F273E4D0F6F; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:23Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:23Z DEBUG request body 'desc=This certificate profile is for renewing certificates to be approved manually by agents.\nvisible=true\nenable=true\nenableBy=admin\nrenewal=true\nauth.instance_id=\nname=Renewal: Renew certificate to be manually approved by agents\ninput.list=i1\ninput.i1.class_id=serialNumRenewInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\nprofileId=caManualRenewal\nclassId=caEnrollImpl\n' 2019-01-17T11:04:23Z DEBUG response status 409 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:23Z DEBUG Error migrating 'caManualRenewal': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:23Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caManualRenewal?action=enable 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 500 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:23 GMT Connection: close 2019-01-17T11:04:23Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:23Z DEBUG Failed to enable profile 'caManualRenewal' (it is probably already enabled) 2019-01-17T11:04:23Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 204 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=B4E3DCDA63CAB35F766099DAEF153F85; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body '' 2019-01-17T11:04:23Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 200 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=A3AB0C403797263769E334BD444A1711; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:23Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:23Z DEBUG request body 'desc=This profile is for enrolling MS Login Certificate\nenable=true\nenableBy=admin\nname=Token User MS Login Certificate Enrollment\nvisible=false\nauth.instance_id=AgentCertAuth\ninput.list=i1\ninput.i1.class_id=nsNKeyCertReqInputImpl\ninput.i1.name=nsNKeyCertReqInputImpl\noutput.list=o1\noutput.o1.class_id=nsNKeyOutputImpl\noutput.o2.name=nsNKeyOutputImpl\npolicyset.list=set1\n#policyset.set1.list=p2,p4,p5,p1,p6,p7,p8,p9,p12,p13,p14\npolicyset.set1.list=p2,p4,p5,p1,p6,p8,p9,p12,p13,p14,p15\npolicyset.set1.p1.constraint.class_id=noConstraintImpl\npolicyset.set1.p1.constraint.name=No Constraint\npolicyset.set1.p1.default.class_id=nsTokenUserKeySubjectNameDefaultImpl\npolicyset.set1.p1.default.name=nsTokenUserKeySubjectNameDefault\npolicyset.set1.p1.default.params.dnpattern=CN=uid=$request.uid$,E=$request.mail$, ou=$request.upn$, o=example\n#changed ldap.enable to true to support SMIME\npolicyset.set1.p1.default.params.ldap.enable=true\npolicyset.set1.p1.default.params.ldap.searchName=uid\npolicyset.set1.p1.default.params.ldapStringAttributes=uid,mail,givenName,sn,upn\npolicyset.set1.p1.default.params.ldap.basedn=ou=People,dc=example,dc=com\npolicyset.set1.p1.default.params.ldap.maxConns=4\npolicyset.set1.p1.default.params.ldap.minConns=1\npolicyset.set1.p1.default.params.ldap.ldapconn.Version=2\npolicyset.set1.p1.default.params.ldap.ldapconn.host=localhost.localdomain\npolicyset.set1.p1.default.params.ldap.ldapconn.port=389\npolicyset.set1.p1.default.params.ldap.ldapconn.secureConn=false\npolicyset.set1.p2.constraint.class_id=noConstraintImpl\npolicyset.set1.p2.constraint.name=No Constraint\npolicyset.set1.p2.default.class_id=validityDefaultImpl\npolicyset.set1.p2.default.name=Validity Default\npolicyset.set1.p2.default.params.range=1825\npolicyset.set1.p2.default.params.startTime=0\npolicyset.set1.p4.constraint.class_id=noConstraintImpl\npolicyset.set1.p4.constraint.name=No Constraint\npolicyset.set1.p4.default.class_id=signingAlgDefaultImpl\npolicyset.set1.p4.default.name=Signing Algorithm Default\npolicyset.set1.p4.default.params.signingAlg=-\npolicyset.set1.p5.constraint.class_id=noConstraintImpl\npolicyset.set1.p5.constraint.name=No Constraint\npolicyset.set1.p5.default.class_id=keyUsageExtDefaultImpl\npolicyset.set1.p5.default.name=Key Usage Extension Default\npolicyset.set1.p5.default.params.keyUsageCritical=true\npolicyset.set1.p5.default.params.keyUsageCrlSign=false\npolicyset.set1.p5.default.params.keyUsageDataEncipherment=false\npolicyset.set1.p5.default.params.keyUsageDecipherOnly=false\npolicyset.set1.p5.default.params.keyUsageDigitalSignature=true\npolicyset.set1.p5.default.params.keyUsageEncipherOnly=false\npolicyset.set1.p5.default.params.keyUsageKeyAgreement=false\npolicyset.set1.p5.default.params.keyUsageKeyCertSign=false\npolicyset.set1.p5.default.params.keyUsageKeyEncipherment=false\npolicyset.set1.p5.default.params.keyUsageNonRepudiation=true\npolicyset.set1.p6.constraint.class_id=noConstraintImpl\npolicyset.set1.p6.constraint.name=No Constraint\npolicyset.set1.p6.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.set1.p6.default.name=Subject Alternative Name Extension Default\npolicyset.set1.p6.default.params.subjAltExtGNEnable_0=true\npolicyset.set1.p6.default.params.subjAltExtGNEnable_1=true\npolicyset.set1.p6.default.params.subjAltExtGNEnable_2=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_3=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_4=false\npolicyset.set1.p6.default.params.subjAltExtPattern_0=$request.mail$\npolicyset.set1.p6.default.params.subjAltExtPattern_1=(UTF8String)1.3.6.1.4.1.311.20.2.3,$request.upn$\npolicyset.set1.p6.default.params.subjAltExtPattern_2=\npolicyset.set1.p6.default.params.subjAltExtPattern_3=\npolicyset.set1.p6.default.params.subjAltExtPattern_4=\npolicyset.set1.p6.default.params.subjAltExtType_0=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_1=OtherName\npolicyset.set1.p6.default.params.subjAltExtType_2=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_3=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_4=RFC822Name\npolicyset.set1.p6.default.params.subjAltNameExtCritical=false\npolicyset.set1.p6.default.params.subjAltNameNumGNs=2\npolicyset.set1.p7.constraint.class_id=noConstraintImpl\npolicyset.set1.p7.constraint.name=No Constraint\npolicyset.set1.p7.default.class_id=certificatePoliciesExtDefaultImpl\npolicyset.set1.p7.default.name=Certificate Policies Extension Default\npolicyset.set1.p7.default.params.Critical=false\npolicyset.set1.p7.default.params.PoliciesExt.num=5\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.CPSURI.enable=true\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.explicitText.value=\n policyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\n policyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.enable=false\n policyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.explicitText.value=\n policyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\n policyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\n policyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p8.constraint.class_id=noConstraintImpl\npolicyset.set1.p8.constraint.name=No Constraint\npolicyset.set1.p8.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.set1.p8.default.name=Subject Key Identifier Default\npolicyset.set1.p9.constraint.class_id=noConstraintImpl\npolicyset.set1.p9.constraint.name=No Constraint\npolicyset.set1.p9.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.set1.p9.default.name=Authority Key Identifier Extension Default\npolicyset.set1.p12.constraint.class_id=basicConstraintsExtConstraintImpl\npolicyset.set1.p12.constraint.name=Basic Constraints Extension Constraint\npolicyset.set1.p12.constraint.params.basicConstraintsCritical=-\npolicyset.set1.p12.constraint.params.basicConstraintsIsCA=-\npolicyset.set1.p12.constraint.params.basicConstraintsMaxPathLen=-1\npolicyset.set1.p12.constraint.params.basicConstraintsMinPathLen=-1\npolicyset.set1.p12.default.class_id=basicConstraintsExtDefaultImpl\npolicyset.set1.p12.default.name=Basic Constraints Extension Default\npolicyset.set1.p12.default.params.basicConstraintsCritical=false\npolicyset.set1.p12.default.params.basicConstraintsIsCA=false\npolicyset.set1.p12.default.params.basicConstraintsPathLen=-1\npolicyset.set1.p13.constraint.class_id=noConstraintImpl\npolicyset.set1.p13.constraint.name=No Constraint\npolicyset.set1.p13.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.set1.p13.default.name=crlDistributionPointsExtDefaultImpl\npolicyset.set1.p13.default.params.crlDistPointsCritical=false\npolicyset.set1.p13.default.params.crlDistPointsNum=1\npolicyset.set1.p13.default.params.crlDistPointsEnable_0=true\npolicyset.set1.p13.default.params.crlDistPointsIssuerName_0=\npolicyset.set1.p13.default.params.crlDistPointsIssuerType_0=\npolicyset.set1.p13.default.params.crlDistPointsPointName_0=http://localhost.localdomain:9443/ca/ee/ca/getCRL?crlIssuingPoint=MasterCRL&op=getCRL\npolicyset.set1.p13.default.params.crlDistPointsPointType_0=URIName\npolicyset.set1.p13.default.params.crlDistPointsReasons_0=\npolicyset.set1.p14.constraint.class_id=noConstraintImpl\npolicyset.set1.p14.constraint.name=No Constraint\npolicyset.set1.p14.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.set1.p14.default.name=AIA Extension Default\npolicyset.set1.p14.default.params.authInfoAccessADEnable_0=true\npolicyset.set1.p14.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.set1.p14.default.params.authInfoAccessADLocation_0=http://localhost.localdomain:9443/ca/ocsp\npolicyset.set1.p14.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.set1.p14.default.params.authInfoAccessCritical=false\npolicyset.set1.p14.default.params.authInfoAccessNumADs=1\npolicyset.set1.p15.constraint.class_id=noConstraintImpl\npolicyset.set1.p15.constraint.name=No Constraint\npolicyset.set1.p15.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.set1.p15.default.name=Extended Key Usage Extension Default\npolicyset.set1.p15.default.params.exKeyUsageCritical=false\npolicyset.set1.p15.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.4.1.311.20.2.2\n\nprofileId=caTokenMSLoginEnrollment\nclassId=caUserCertEnrollImpl\n' 2019-01-17T11:04:23Z DEBUG response status 409 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:23Z DEBUG Error migrating 'caTokenMSLoginEnrollment': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:23Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caTokenMSLoginEnrollment?action=enable 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 500 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:23 GMT Connection: close 2019-01-17T11:04:23Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:23Z DEBUG Failed to enable profile 'caTokenMSLoginEnrollment' (it is probably already enabled) 2019-01-17T11:04:23Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 204 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=19D4A46CC8F8C51C2B49937A66B41535; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body '' 2019-01-17T11:04:23Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 200 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=DB933D6415E57FD273F9526BAEEA46B8; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:23Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:23Z DEBUG request body 'desc=This certificate profile is for renewing a token certificate\nvisible=false\nenable=true\nenableBy=admin\nrenewal=true\nauth.instance_id=AgentCertAuth\nname=smart card token signing cert renewal profile\ninput.list=i1\ninput.i1.class_id=serialNumRenewInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\nprofileId=caTokenUserSigningKeyRenewal\nclassId=caUserCertEnrollImpl\n' 2019-01-17T11:04:23Z DEBUG response status 409 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:23Z DEBUG Error migrating 'caTokenUserSigningKeyRenewal': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:23Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caTokenUserSigningKeyRenewal?action=enable 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 500 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:23 GMT Connection: close 2019-01-17T11:04:23Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:23Z DEBUG Failed to enable profile 'caTokenUserSigningKeyRenewal' (it is probably already enabled) 2019-01-17T11:04:23Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 204 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=5392259F1F0D06CFCAAAF298A9FAA8EA; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body '' 2019-01-17T11:04:23Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 200 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=C94C609850E588C9B63DF9A13B87A7E8; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:23Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:23Z DEBUG request body 'desc=This certificate profile is for renewing a token encryption certificate\nvisible=false\nenable=true\nenableBy=admin\nrenewal=true\nauth.instance_id=AgentCertAuth\nname=smart card token encryption cert renewal profile\ninput.list=i1\ninput.i1.class_id=serialNumRenewInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\nprofileId=caTokenUserEncryptionKeyRenewal\nclassId=caUserCertEnrollImpl\n' 2019-01-17T11:04:23Z DEBUG response status 409 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:23Z DEBUG Error migrating 'caTokenUserEncryptionKeyRenewal': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:23Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caTokenUserEncryptionKeyRenewal?action=enable 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 500 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:23 GMT Connection: close 2019-01-17T11:04:23Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:23Z DEBUG Failed to enable profile 'caTokenUserEncryptionKeyRenewal' (it is probably already enabled) 2019-01-17T11:04:23Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 204 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=FB2045DFBACE865716809F2F3D18CDD3; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body '' 2019-01-17T11:04:23Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 200 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=921641AF3C88639F7E228D2728B6C67F; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:23Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:23Z DEBUG request body 'desc=This certificate profile is for renewing a token authentication certificate\nvisible=false\nenable=true\nenableBy=admin\nrenewal=true\nauth.instance_id=AgentCertAuth\nname=smart card token authentication cert renewal profile\ninput.list=i1\ninput.i1.class_id=serialNumRenewInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\nprofileId=caTokenUserAuthKeyRenewal\nclassId=caUserCertEnrollImpl\n' 2019-01-17T11:04:23Z DEBUG response status 409 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:23Z DEBUG Error migrating 'caTokenUserAuthKeyRenewal': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:23Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caTokenUserAuthKeyRenewal?action=enable 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 500 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:23 GMT Connection: close 2019-01-17T11:04:23Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:23Z DEBUG Failed to enable profile 'caTokenUserAuthKeyRenewal' (it is probably already enabled) 2019-01-17T11:04:23Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 204 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=BEC346EBA0105128465778631D1ABE4A; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body '' 2019-01-17T11:04:23Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 200 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=7E27E6469DCC50314870882FA13F61BE; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:23Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:23Z DEBUG request body 'desc=This is an IPA profile for enrolling Jar Signing certificates.\nenable=true\nenableBy=admin\nname=Manual Jar Signing Certificate Enrollment\nvisible=false\nauth.class_id=\nauth.instance_id=raCertAuth\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=caJarSigningSet\npolicyset.caJarSigningSet.list=1,2,3,4,5,6\npolicyset.caJarSigningSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.caJarSigningSet.1.constraint.name=Subject Name Constraint\npolicyset.caJarSigningSet.1.constraint.params.accept=true\npolicyset.caJarSigningSet.1.constraint.params.pattern=.*\npolicyset.caJarSigningSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.caJarSigningSet.1.default.name=Subject Name Default\npolicyset.caJarSigningSet.1.default.params.name=\npolicyset.caJarSigningSet.2.constraint.class_id=validityConstraintImpl\npolicyset.caJarSigningSet.2.constraint.name=Validity Constraint\npolicyset.caJarSigningSet.2.constraint.params.notAfterCheck=false\npolicyset.caJarSigningSet.2.constraint.params.notBeforeCheck=false\npolicyset.caJarSigningSet.2.constraint.params.range=2922\npolicyset.caJarSigningSet.2.default.class_id=validityDefaultImpl\npolicyset.caJarSigningSet.2.default.name=Validity Default\npolicyset.caJarSigningSet.2.default.params.range=1461\npolicyset.caJarSigningSet.2.default.params.startTime=0\npolicyset.caJarSigningSet.3.constraint.class_id=keyConstraintImpl\npolicyset.caJarSigningSet.3.constraint.name=Key Constraint\npolicyset.caJarSigningSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.caJarSigningSet.3.constraint.params.keyType=RSA\npolicyset.caJarSigningSet.3.default.class_id=userKeyDefaultImpl\npolicyset.caJarSigningSet.3.default.name=Key Default\npolicyset.caJarSigningSet.4.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.caJarSigningSet.4.constraint.name=Key Usage Extension Constraint\npolicyset.caJarSigningSet.4.constraint.params.keyUsageCritical=-\npolicyset.caJarSigningSet.4.constraint.params.keyUsageCrlSign=-\npolicyset.caJarSigningSet.4.constraint.params.keyUsageDataEncipherment=-\npolicyset.caJarSigningSet.4.constraint.params.keyUsageDecipherOnly=-\npolicyset.caJarSigningSet.4.constraint.params.keyUsageDigitalSignature=-\npolicyset.caJarSigningSet.4.constraint.params.keyUsageEncipherOnly=-\npolicyset.caJarSigningSet.4.constraint.params.keyUsageKeyAgreement=-\npolicyset.caJarSigningSet.4.constraint.params.keyUsageKeyCertSign=-\npolicyset.caJarSigningSet.4.constraint.params.keyUsageKeyEncipherment=-\npolicyset.caJarSigningSet.4.constraint.params.keyUsageNonRepudiation=-\npolicyset.caJarSigningSet.4.default.class_id=keyUsageExtDefaultImpl\npolicyset.caJarSigningSet.4.default.name=Key Usage Default\npolicyset.caJarSigningSet.4.default.params.keyUsageCritical=true\npolicyset.caJarSigningSet.4.default.params.keyUsageCrlSign=false\npolicyset.caJarSigningSet.4.default.params.keyUsageDataEncipherment=false\npolicyset.caJarSigningSet.4.default.params.keyUsageDecipherOnly=false\npolicyset.caJarSigningSet.4.default.params.keyUsageDigitalSignature=true\npolicyset.caJarSigningSet.4.default.params.keyUsageEncipherOnly=false\npolicyset.caJarSigningSet.4.default.params.keyUsageKeyAgreement=false\npolicyset.caJarSigningSet.4.default.params.keyUsageKeyCertSign=true\npolicyset.caJarSigningSet.4.default.params.keyUsageKeyEncipherment=false\npolicyset.caJarSigningSet.4.default.params.keyUsageNonRepudiation=false\npolicyset.caJarSigningSet.5.constraint.class_id=nsCertTypeExtConstraintImpl\npolicyset.caJarSigningSet.5.constraint.name=Netscape Certificate Type Extension Constraint\npolicyset.caJarSigningSet.5.constraint.params.nsCertCritical=-\npolicyset.caJarSigningSet.5.constraint.params.nsCertEmail=-\npolicyset.caJarSigningSet.5.constraint.params.nsCertEmailCA=-\npolicyset.caJarSigningSet.5.constraint.params.nsCertObjectSigning=-\npolicyset.caJarSigningSet.5.constraint.params.nsCertObjectSigningCA=-\npolicyset.caJarSigningSet.5.constraint.params.nsCertSSLCA=-\npolicyset.caJarSigningSet.5.constraint.params.nsCertSSLClient=-\npolicyset.caJarSigningSet.5.constraint.params.nsCertSSLServer=-\npolicyset.caJarSigningSet.5.default.class_id=nsCertTypeExtDefaultImpl\npolicyset.caJarSigningSet.5.default.name=Netscape Certificate Type Extension Default\npolicyset.caJarSigningSet.5.default.params.nsCertCritical=false\npolicyset.caJarSigningSet.5.default.params.nsCertEmail=false\npolicyset.caJarSigningSet.5.default.params.nsCertEmailCA=false\npolicyset.caJarSigningSet.5.default.params.nsCertObjectSigning=true\npolicyset.caJarSigningSet.5.default.params.nsCertObjectSigningCA=false\npolicyset.caJarSigningSet.5.default.params.nsCertSSLCA=false\npolicyset.caJarSigningSet.5.default.params.nsCertSSLClient=false\npolicyset.caJarSigningSet.5.default.params.nsCertSSLServer=false\npolicyset.caJarSigningSet.6.constraint.class_id=signingAlgConstraintImpl\npolicyset.caJarSigningSet.6.constraint.name=No Constraint\npolicyset.caJarSigningSet.6.constraint.params.signingAlgsAllowed=MD5withRSA,MD2withRSA,SHA1withRSA,SHA256withRSA,SHA512withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.caJarSigningSet.6.default.class_id=signingAlgDefaultImpl\npolicyset.caJarSigningSet.6.default.name=Signing Alg\npolicyset.caJarSigningSet.6.default.params.signingAlg=-\nprofileId=caJarSigningCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:23Z DEBUG response status 409 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:23Z DEBUG Error migrating 'caJarSigningCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:23Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caJarSigningCert?action=enable 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 500 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:23 GMT Connection: close 2019-01-17T11:04:23Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:23Z DEBUG Failed to enable profile 'caJarSigningCert' (it is probably already enabled) 2019-01-17T11:04:23Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 204 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=4A1ABB20F84369AB27EFDC7775D2FBA8; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body '' 2019-01-17T11:04:23Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 200 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=0B56B195A13ECED339E6BC61CFABC412; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:23Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:23Z DEBUG request body 'desc=This certificate profile is for enrolling server certificates with IPA-RA agent authentication.\nvisible=false\nenable=true\nenableBy=admin\nauth.instance_id=raCertAuth\nname=IPA-RA Agent-Authenticated Server Certificate Enrollment\ninput.list=i1,i2\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.pattern=CN=[^,]+,.+\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.default.class_id=subjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=CN=$request.req_subject_name.cn$, OU=pki-ipa, O=IPA \npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.range=740\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=731\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.9.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.serverCertSet.9.default.name=CRL Distribution Points Extension Default\npolicyset.serverCertSet.9.default.params.crlDistPointsCritical=false\npolicyset.serverCertSet.9.default.params.crlDistPointsNum=1\npolicyset.serverCertSet.9.default.params.crlDistPointsEnable_0=true\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerName_0=\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerType_0=\npolicyset.serverCertSet.9.default.params.crlDistPointsPointName_0=https://ipa.example.com/ipa/crl/MasterCRL.bin\npolicyset.serverCertSet.9.default.params.crlDistPointsPointType_0=URIName\npolicyset.serverCertSet.9.default.params.crlDistPointsReasons_0=\nprofileId=caIPAserviceCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:23Z DEBUG response status 409 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:23Z DEBUG Error migrating 'caIPAserviceCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:23Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caIPAserviceCert?action=enable 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 500 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:23 GMT Connection: close 2019-01-17T11:04:23Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:23Z DEBUG Failed to enable profile 'caIPAserviceCert' (it is probably already enabled) 2019-01-17T11:04:23Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 204 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=9FD9352C525338013D9ED2269841E71E; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body '' 2019-01-17T11:04:23Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 200 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=4A20AF9D421F8B0A3CAC4AC688418A58; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:23Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:23Z DEBUG request body 'desc=This certificate profile is for enrolling user encryption certificates with option to archive keys.\nvisible=false\nenable=true\nenableBy=admin\nname=Manual User Encryption Certificates Enrollment\nauth.class_id=\ninput.list=i1,i2,i3\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=subjectNameInputImpl\ninput.i3.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=encryptionCertSet\npolicyset.encryptionCertSet.list=1,2,3,4,5,6,7,8,9\npolicyset.encryptionCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.encryptionCertSet.1.constraint.name=Subject Name Constraint\npolicyset.encryptionCertSet.1.constraint.params.pattern=CN=.*\npolicyset.encryptionCertSet.1.constraint.params.accept=true\npolicyset.encryptionCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.encryptionCertSet.1.default.name=Subject Name Default\npolicyset.encryptionCertSet.1.default.params.name=\npolicyset.encryptionCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.encryptionCertSet.2.constraint.name=Validity Constraint\npolicyset.encryptionCertSet.2.constraint.params.range=365\npolicyset.encryptionCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.encryptionCertSet.2.constraint.params.notAfterCheck=false\npolicyset.encryptionCertSet.2.default.class_id=validityDefaultImpl\npolicyset.encryptionCertSet.2.default.name=Validity Default\npolicyset.encryptionCertSet.2.default.params.range=180\npolicyset.encryptionCertSet.2.default.params.startTime=0\npolicyset.encryptionCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.encryptionCertSet.3.constraint.name=Key Constraint\npolicyset.encryptionCertSet.3.constraint.params.keyType=RSA\npolicyset.encryptionCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.encryptionCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.encryptionCertSet.3.default.name=Key Default\npolicyset.encryptionCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.encryptionCertSet.4.constraint.name=No Constraint\npolicyset.encryptionCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.encryptionCertSet.4.default.name=Authority Key Identifier Default\npolicyset.encryptionCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.encryptionCertSet.5.constraint.name=No Constraint\npolicyset.encryptionCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.encryptionCertSet.5.default.name=AIA Extension Default\npolicyset.encryptionCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.encryptionCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.encryptionCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.encryptionCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.encryptionCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.encryptionCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.encryptionCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.encryptionCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.encryptionCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.encryptionCertSet.6.constraint.params.keyUsageDigitalSignature=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageNonRepudiation=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageDataEncipherment=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.encryptionCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.encryptionCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.encryptionCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.encryptionCertSet.6.default.name=Key Usage Default\npolicyset.encryptionCertSet.6.default.params.keyUsageCritical=true\npolicyset.encryptionCertSet.6.default.params.keyUsageDigitalSignature=false\npolicyset.encryptionCertSet.6.default.params.keyUsageNonRepudiation=false\npolicyset.encryptionCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.encryptionCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.encryptionCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.encryptionCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.encryptionCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.encryptionCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.encryptionCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.encryptionCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.encryptionCertSet.7.constraint.name=No Constraint\npolicyset.encryptionCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.encryptionCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.encryptionCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.encryptionCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.encryptionCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.encryptionCertSet.8.constraint.name=No Constraint\npolicyset.encryptionCertSet.8.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.encryptionCertSet.8.default.name=Subject Alt Name Constraint\npolicyset.encryptionCertSet.8.default.params.subjAltNameExtCritical=false\npolicyset.encryptionCertSet.8.default.params.subjAltExtType_0=RFC822Name\npolicyset.encryptionCertSet.8.default.params.subjAltExtPattern_0=$request.requestor_email$\npolicyset.encryptionCertSet.8.default.params.subjAltExtGNEnable_0=true\npolicyset.encryptionCertSet.8.default.params.subjAltNameNumGNs=1\npolicyset.encryptionCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.encryptionCertSet.9.constraint.name=No Constraint\npolicyset.encryptionCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.encryptionCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.encryptionCertSet.9.default.name=Signing Alg\npolicyset.encryptionCertSet.9.default.params.signingAlg=-\n\nprofileId=caEncUserCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:23Z DEBUG response status 409 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:23Z DEBUG Error migrating 'caEncUserCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:23Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caEncUserCert?action=enable 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 500 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:23 GMT Connection: close 2019-01-17T11:04:23Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:23Z DEBUG Failed to enable profile 'caEncUserCert' (it is probably already enabled) 2019-01-17T11:04:23Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 204 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=FFB2BC75EF64C2E62943DFB422D15B3A; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body '' 2019-01-17T11:04:23Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 200 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=D1378C823105F08991121834C73F1300; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:23Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:23Z DEBUG request body 'desc=This certificate profile is for enrolling user signing certificates.\nvisible=false\nenable=true\nenableBy=admin\nname=Manual User Signing Certificate Enrollment\nauth.class_id=\ninput.list=i1,i2,i3\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=subjectNameInputImpl\ninput.i3.class_id=submitterInfoInputImpl\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=signingCertSet\npolicyset.signingCertSet.list=1,2,3,4,5,6,7,8,9\npolicyset.signingCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.signingCertSet.1.constraint.name=Subject Name Constraint\npolicyset.signingCertSet.1.constraint.params.pattern=CN=.*\npolicyset.signingCertSet.1.constraint.params.accept=true\npolicyset.signingCertSet.1.default.class_id=userSubjectNameDefaultImpl\npolicyset.signingCertSet.1.default.name=Subject Name Default\npolicyset.signingCertSet.1.default.params.name=\npolicyset.signingCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.signingCertSet.2.constraint.name=Validity Constraint\npolicyset.signingCertSet.2.constraint.params.range=365\npolicyset.signingCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.signingCertSet.2.constraint.params.notAfterCheck=false\npolicyset.signingCertSet.2.default.class_id=validityDefaultImpl\npolicyset.signingCertSet.2.default.name=Validity Default\npolicyset.signingCertSet.2.default.params.range=180\npolicyset.signingCertSet.2.default.params.startTime=0\npolicyset.signingCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.signingCertSet.3.constraint.name=Key Constraint\npolicyset.signingCertSet.3.constraint.params.keyType=RSA\npolicyset.signingCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096\npolicyset.signingCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.signingCertSet.3.default.name=Key Default\npolicyset.signingCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.signingCertSet.4.constraint.name=No Constraint\npolicyset.signingCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.signingCertSet.4.default.name=Authority Key Identifier Default\npolicyset.signingCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.signingCertSet.5.constraint.name=No Constraint\npolicyset.signingCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.signingCertSet.5.default.name=AIA Extension Default\npolicyset.signingCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.signingCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.signingCertSet.5.default.params.authInfoAccessADLocation_0=\npolicyset.signingCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.signingCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.signingCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.signingCertSet.6.constraint.class_id=noConstraintImpl\npolicyset.signingCertSet.6.constraint.name=No Constraint\npolicyset.signingCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.signingCertSet.6.default.name=Key Usage Default\npolicyset.signingCertSet.6.default.params.keyUsageCritical=true\npolicyset.signingCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.signingCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.signingCertSet.6.default.params.keyUsageDataEncipherment=false\npolicyset.signingCertSet.6.default.params.keyUsageKeyEncipherment=false\npolicyset.signingCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.signingCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.signingCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.signingCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.signingCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.signingCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.signingCertSet.7.constraint.name=No Constraint\npolicyset.signingCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.signingCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.signingCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.signingCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.2,1.3.6.1.5.5.7.3.4\npolicyset.signingCertSet.8.constraint.class_id=noConstraintImpl\npolicyset.signingCertSet.8.constraint.name=No Constraint\npolicyset.signingCertSet.8.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.signingCertSet.8.default.name=Subject Alt Name Constraint\npolicyset.signingCertSet.8.default.params.subjAltNameExtCritical=false\npolicyset.signingCertSet.8.default.params.subjAltExtType_0=RFC822Name\npolicyset.signingCertSet.8.default.params.subjAltExtPattern_0=$request.requestor_email$\npolicyset.signingCertSet.8.default.params.subjAltExtGNEnable_0=true\npolicyset.signingCertSet.8.default.params.subjAltNameNumGNs=1\npolicyset.signingCertSet.9.constraint.class_id=signingAlgConstraintImpl\npolicyset.signingCertSet.9.constraint.name=No Constraint\npolicyset.signingCertSet.9.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withRSA,SHA384withEC,SHA512withEC\npolicyset.signingCertSet.9.default.class_id=signingAlgDefaultImpl\npolicyset.signingCertSet.9.default.name=Signing Alg\npolicyset.signingCertSet.9.default.params.signingAlg=-\n\nprofileId=caSigningUserCert\nclassId=caEnrollImpl\n' 2019-01-17T11:04:23Z DEBUG response status 409 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:23Z DEBUG Error migrating 'caSigningUserCert': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:23Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caSigningUserCert?action=enable 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 500 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:23 GMT Connection: close 2019-01-17T11:04:23Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:23Z DEBUG Failed to enable profile 'caSigningUserCert' (it is probably already enabled) 2019-01-17T11:04:23Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 204 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=61F74ED974E48F1EF0EFF69ACCD14002; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body '' 2019-01-17T11:04:23Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 200 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=F151752BAEA13F4152F2BFA6EBFE8C04; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:23Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:23Z DEBUG request body 'desc=This profile is for enrolling Token User Delegate Authentication key\nenable=true\nenableBy=admin\nname=Token User Delegate Authentication Certificate Enrollment\nvisible=false\nauth.instance_id=AgentCertAuth\ninput.list=i1,i2,i3\ninput.i1.class_id=nsNKeyCertReqInputImpl\ninput.i1.name=nsNKeyCertReqInputImpl\ninput.i2.class_id=subjectDNInputImpl\ninput.i2.name=subjectDNInputImpl\ninput.i3.class_id=subjectAltNameExtInputImpl\ninput.i3.name=subjectAltNameExtInputImpl\noutput.list=o1\noutput.o1.class_id=nsNKeyOutputImpl\noutput.o1.name=nsNKeyOutputImpl\npolicyset.list=set1\n#policyset.set1.list=p2,p4,p5,p1,p6,p7,p8,p9,p12,p13,p14\npolicyset.set1.list=p2,p4,p5,p1,p6,p8,p9,p12\npolicyset.set1.p1.constraint.class_id=subjectNameConstraintImpl\npolicyset.set1.p1.constraint.name=Subject Name Constraint\npolicyset.set1.p1.constraint.params.pattern=.*\npolicyset.set1.p1.constraint.params.accept=true\npolicyset.set1.p1.default.class_id=userSubjectNameDefaultImpl\npolicyset.set1.p1.default.name=Subject Name Default\npolicyset.set1.p1.default.params.name=\n#changed ldap.enable to true to support SMIME\npolicyset.set1.p1.default.params.ldap.enable=false\npolicyset.set1.p1.default.params.ldap.searchName=uid\npolicyset.set1.p1.default.params.ldapStringAttributes=uid,mail\npolicyset.set1.p1.default.params.ldap.basedn=\npolicyset.set1.p1.default.params.ldap.maxConns=4\npolicyset.set1.p1.default.params.ldap.minConns=1\npolicyset.set1.p1.default.params.ldap.ldapconn.Version=2\npolicyset.set1.p1.default.params.ldap.ldapconn.host=\npolicyset.set1.p1.default.params.ldap.ldapconn.port=\npolicyset.set1.p1.default.params.ldap.ldapconn.secureConn=false\npolicyset.set1.p2.constraint.class_id=noConstraintImpl\npolicyset.set1.p2.constraint.name=No Constraint\npolicyset.set1.p2.default.class_id=validityDefaultImpl\npolicyset.set1.p2.default.name=Validity Default\npolicyset.set1.p2.default.params.range=1825\npolicyset.set1.p2.default.params.startTime=0\npolicyset.set1.p4.constraint.class_id=noConstraintImpl\npolicyset.set1.p4.constraint.name=No Constraint\npolicyset.set1.p4.default.class_id=signingAlgDefaultImpl\npolicyset.set1.p4.default.name=Signing Algorithm Default\npolicyset.set1.p4.default.params.signingAlg=-\npolicyset.set1.p5.constraint.class_id=noConstraintImpl\npolicyset.set1.p5.constraint.name=No Constraint\npolicyset.set1.p5.default.class_id=keyUsageExtDefaultImpl\npolicyset.set1.p5.default.name=Key Usage Extension Default\npolicyset.set1.p5.default.params.keyUsageCritical=true\npolicyset.set1.p5.default.params.keyUsageCrlSign=false\npolicyset.set1.p5.default.params.keyUsageDataEncipherment=false\npolicyset.set1.p5.default.params.keyUsageDecipherOnly=false\npolicyset.set1.p5.default.params.keyUsageDigitalSignature=true\npolicyset.set1.p5.default.params.keyUsageEncipherOnly=false\npolicyset.set1.p5.default.params.keyUsageKeyAgreement=false\npolicyset.set1.p5.default.params.keyUsageKeyCertSign=false\npolicyset.set1.p5.default.params.keyUsageKeyEncipherment=false\npolicyset.set1.p5.default.params.keyUsageNonRepudiation=true\npolicyset.set1.p6.constraint.class_id=noConstraintImpl\npolicyset.set1.p6.constraint.name=No Constraint\npolicyset.set1.p6.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.set1.p6.default.name=Subject Alternative Name Extension Default\npolicyset.set1.p6.default.params.subjAltExtGNEnable_0=true\npolicyset.set1.p6.default.params.subjAltExtGNEnable_1=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_2=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_3=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_4=false\npolicyset.set1.p6.default.params.subjAltExtPattern_0=(UTF8String)1.3.6.1.4.1.311.20.2.3,$request.req_san_pattern_0$\npolicyset.set1.p6.default.params.subjAltExtPattern_1=\npolicyset.set1.p6.default.params.subjAltExtPattern_2=\npolicyset.set1.p6.default.params.subjAltExtPattern_3=\npolicyset.set1.p6.default.params.subjAltExtPattern_4=\npolicyset.set1.p6.default.params.subjAltExtType_0=OtherName\npolicyset.set1.p6.default.params.subjAltExtType_1=OtherName\npolicyset.set1.p6.default.params.subjAltExtType_2=OtherName\npolicyset.set1.p6.default.params.subjAltExtType_3=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_4=RFC822Name\npolicyset.set1.p6.default.params.subjAltNameExtCritical=false\npolicyset.set1.p6.default.params.subjAltNameNumGNs=1\npolicyset.set1.p7.constraint.class_id=noConstraintImpl\npolicyset.set1.p7.constraint.name=No Constraint\npolicyset.set1.p7.default.class_id=certificatePoliciesExtDefaultImpl\npolicyset.set1.p7.default.name=Certificate Policies Extension Default\npolicyset.set1.p7.default.params.Critical=false\npolicyset.set1.p7.default.params.PoliciesExt.num=5\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.CPSURI.enable=true\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p8.constraint.class_id=noConstraintImpl\npolicyset.set1.p8.constraint.name=No Constraint\npolicyset.set1.p8.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.set1.p8.default.name=Subject Key Identifier Default\npolicyset.set1.p9.constraint.class_id=noConstraintImpl\npolicyset.set1.p9.constraint.name=No Constraint\npolicyset.set1.p9.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.set1.p9.default.name=Authority Key Identifier Extension Default\npolicyset.set1.10.constraint.class_id=renewGracePeriodConstraintImpl\npolicyset.set1.10.constraint.name=Renewal Grace Period Constraint\npolicyset.set1.10.constraint.params.renewal.graceBefore=30\npolicyset.set1.10.constraint.params.renewal.graceAfter=30\npolicyset.set1.10.default.class_id=noDefaultImpl\npolicyset.set1.10.default.name=No Default\npolicyset.set1.p12.constraint.class_id=basicConstraintsExtConstraintImpl\npolicyset.set1.p12.constraint.name=Basic Constraints Extension Constraint\npolicyset.set1.p12.constraint.params.basicConstraintsCritical=-\npolicyset.set1.p12.constraint.params.basicConstraintsIsCA=-\npolicyset.set1.p12.constraint.params.basicConstraintsMaxPathLen=-1\npolicyset.set1.p12.constraint.params.basicConstraintsMinPathLen=-1\npolicyset.set1.p12.default.class_id=basicConstraintsExtDefaultImpl\npolicyset.set1.p12.default.name=Basic Constraints Extension Default\npolicyset.set1.p12.default.params.basicConstraintsCritical=false\npolicyset.set1.p12.default.params.basicConstraintsIsCA=false\npolicyset.set1.p12.default.params.basicConstraintsPathLen=-1\npolicyset.set1.p13.constraint.class_id=noConstraintImpl\npolicyset.set1.p13.constraint.name=No Constraint\npolicyset.set1.p13.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.set1.p13.default.name=crlDistributionPointsExtDefaultImpl\npolicyset.set1.p13.default.params.crlDistPointsCritical=false\npolicyset.set1.p13.default.params.crlDistPointsNum=1\npolicyset.set1.p13.default.params.crlDistPointsEnable_0=false\npolicyset.set1.p13.default.params.crlDistPointsIssuerName_0=\npolicyset.set1.p13.default.params.crlDistPointsIssuerType_0=\npolicyset.set1.p13.default.params.crlDistPointsPointName_0=\npolicyset.set1.p13.default.params.crlDistPointsPointType_0=URIName\npolicyset.set1.p13.default.params.crlDistPointsReasons_0=\npolicyset.set1.p14.constraint.class_id=noConstraintImpl\npolicyset.set1.p14.constraint.name=No Constraint\npolicyset.set1.p14.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.set1.p14.default.name=AIA Extension Default\npolicyset.set1.p14.default.params.authInfoAccessADEnable_0=false\npolicyset.set1.p14.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.set1.p14.default.params.authInfoAccessADLocation_0=\npolicyset.set1.p14.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.set1.p14.default.params.authInfoAccessCritical=false\npolicyset.set1.p14.default.params.authInfoAccessNumADs=1\nprofileId=caTokenUserDelegateAuthKeyEnrollment\nclassId=caUserCertEnrollImpl\n' 2019-01-17T11:04:23Z DEBUG response status 409 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:23Z DEBUG Error migrating 'caTokenUserDelegateAuthKeyEnrollment': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:23Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caTokenUserDelegateAuthKeyEnrollment?action=enable 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 500 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:23 GMT Connection: close 2019-01-17T11:04:23Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:23Z DEBUG Failed to enable profile 'caTokenUserDelegateAuthKeyEnrollment' (it is probably already enabled) 2019-01-17T11:04:23Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 204 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=CEAA098FF597D2435AE3D352DDE369F3; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body '' 2019-01-17T11:04:23Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 200 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=0760FC891DAF1486183C8872F616C767; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:23Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/raw 2019-01-17T11:04:23Z DEBUG request body 'desc=This profile is for enrolling Token User Delegate Signing key\nenable=true\nenableBy=admin\nname=Token User Delegate Signing Certificate Enrollment\nvisible=false\nauth.instance_id=AgentCertAuth\ninput.list=i1,i2,i3\ninput.i1.class_id=nsNKeyCertReqInputImpl\ninput.i1.name=nsNKeyCertReqInputImpl\ninput.i2.class_id=subjectDNInputImpl\ninput.i2.name=subjectDNInputImpl\ninput.i3.class_id=subjectAltNameExtInputImpl\ninput.i3.name=subjectAltNameExtInputImpl\noutput.list=o1\noutput.o1.class_id=nsNKeyOutputImpl\noutput.o1.name=nsNKeyOutputImpl\npolicyset.list=set1\n#policyset.set1.list=p2,p4,p5,p1,p6,p7,p8,p9,p12,p13,p14\npolicyset.set1.list=p2,p4,p5,p1,p6,p8,p9,p12\npolicyset.set1.p1.constraint.class_id=subjectNameConstraintImpl\npolicyset.set1.p1.constraint.name=Subject Name Constraint\npolicyset.set1.p1.constraint.params.pattern=.*\npolicyset.set1.p1.constraint.params.accept=true\npolicyset.set1.p1.default.class_id=userSubjectNameDefaultImpl\npolicyset.set1.p1.default.name=Subject Name Default\npolicyset.set1.p1.default.params.dnpattern=UID=$request.uid$, O=Token Key User\n#changed ldap.enable to true to support SMIME\npolicyset.set1.p1.default.params.ldap.enable=false\npolicyset.set1.p1.default.params.ldap.searchName=uid\npolicyset.set1.p1.default.params.ldapStringAttributes=uid,mail\npolicyset.set1.p1.default.params.ldap.basedn=\npolicyset.set1.p1.default.params.ldap.maxConns=4\npolicyset.set1.p1.default.params.ldap.minConns=1\npolicyset.set1.p1.default.params.ldap.ldapconn.Version=2\npolicyset.set1.p1.default.params.ldap.ldapconn.host=\npolicyset.set1.p1.default.params.ldap.ldapconn.port=\npolicyset.set1.p1.default.params.ldap.ldapconn.secureConn=false\npolicyset.set1.p2.constraint.class_id=noConstraintImpl\npolicyset.set1.p2.constraint.name=No Constraint\npolicyset.set1.p2.default.class_id=validityDefaultImpl\npolicyset.set1.p2.default.name=Validity Default\npolicyset.set1.p2.default.params.range=1825\npolicyset.set1.p2.default.params.startTime=0\npolicyset.set1.p4.constraint.class_id=noConstraintImpl\npolicyset.set1.p4.constraint.name=No Constraint\npolicyset.set1.p4.default.class_id=signingAlgDefaultImpl\npolicyset.set1.p4.default.name=Signing Algorithm Default\npolicyset.set1.p4.default.params.signingAlg=-\npolicyset.set1.p5.constraint.class_id=noConstraintImpl\npolicyset.set1.p5.constraint.name=No Constraint\npolicyset.set1.p5.default.class_id=keyUsageExtDefaultImpl\npolicyset.set1.p5.default.name=Key Usage Extension Default\npolicyset.set1.p5.default.params.keyUsageCritical=true\npolicyset.set1.p5.default.params.keyUsageCrlSign=false\npolicyset.set1.p5.default.params.keyUsageDataEncipherment=false\npolicyset.set1.p5.default.params.keyUsageDecipherOnly=false\npolicyset.set1.p5.default.params.keyUsageDigitalSignature=true\npolicyset.set1.p5.default.params.keyUsageEncipherOnly=false\npolicyset.set1.p5.default.params.keyUsageKeyAgreement=false\npolicyset.set1.p5.default.params.keyUsageKeyCertSign=false\npolicyset.set1.p5.default.params.keyUsageKeyEncipherment=false\npolicyset.set1.p5.default.params.keyUsageNonRepudiation=true\npolicyset.set1.p6.constraint.class_id=noConstraintImpl\npolicyset.set1.p6.constraint.name=No Constraint\npolicyset.set1.p6.default.class_id=subjectAltNameExtDefaultImpl\npolicyset.set1.p6.default.name=Subject Alternative Name Extension Default\npolicyset.set1.p6.default.params.subjAltExtGNEnable_0=true\npolicyset.set1.p6.default.params.subjAltExtGNEnable_1=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_2=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_3=false\npolicyset.set1.p6.default.params.subjAltExtGNEnable_4=false\npolicyset.set1.p6.default.params.subjAltExtPattern_0=$request.req_san_pattern_0$\npolicyset.set1.p6.default.params.subjAltExtPattern_1=\npolicyset.set1.p6.default.params.subjAltExtPattern_2=\npolicyset.set1.p6.default.params.subjAltExtPattern_3=\npolicyset.set1.p6.default.params.subjAltExtPattern_4=\npolicyset.set1.p6.default.params.subjAltExtType_0=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_1=OtherName\npolicyset.set1.p6.default.params.subjAltExtType_2=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_3=RFC822Name\npolicyset.set1.p6.default.params.subjAltExtType_4=RFC822Name\npolicyset.set1.p6.default.params.subjAltNameExtCritical=false\npolicyset.set1.p6.default.params.subjAltNameNumGNs=1\npolicyset.set1.p7.constraint.class_id=noConstraintImpl\npolicyset.set1.p7.constraint.name=No Constraint\npolicyset.set1.p7.default.class_id=certificatePoliciesExtDefaultImpl\npolicyset.set1.p7.default.name=Certificate Policies Extension Default\npolicyset.set1.p7.default.params.Critical=false\npolicyset.set1.p7.default.params.PoliciesExt.num=5\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.CPSURI.enable=true\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy0.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy1.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy2.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy3.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.policyId=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.CPSURI.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.CPSURI.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.enable=false\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.explicitText.value=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.noticeReference.noticeNumbers=\npolicyset.set1.p7.default.params.PoliciesExt.certPolicy4.PolicyQualifiers0.usernotice.noticeReference.organization=\npolicyset.set1.p8.constraint.class_id=noConstraintImpl\npolicyset.set1.p8.constraint.name=No Constraint\npolicyset.set1.p8.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.set1.p8.default.name=Subject Key Identifier Default\npolicyset.set1.p9.constraint.class_id=noConstraintImpl\npolicyset.set1.p9.constraint.name=No Constraint\npolicyset.set1.p9.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.set1.p9.default.name=Authority Key Identifier Extension Default\npolicyset.set1.10.constraint.class_id=renewGracePeriodConstraintImpl\npolicyset.set1.10.constraint.name=Renewal Grace Period Constraint\npolicyset.set1.10.constraint.params.renewal.graceBefore=30\npolicyset.set1.10.constraint.params.renewal.graceAfter=30\npolicyset.set1.10.default.class_id=noDefaultImpl\npolicyset.set1.10.default.name=No Default\npolicyset.set1.p12.constraint.class_id=basicConstraintsExtConstraintImpl\npolicyset.set1.p12.constraint.name=Basic Constraints Extension Constraint\npolicyset.set1.p12.constraint.params.basicConstraintsCritical=-\npolicyset.set1.p12.constraint.params.basicConstraintsIsCA=-\npolicyset.set1.p12.constraint.params.basicConstraintsMaxPathLen=-1\npolicyset.set1.p12.constraint.params.basicConstraintsMinPathLen=-1\npolicyset.set1.p12.default.class_id=basicConstraintsExtDefaultImpl\npolicyset.set1.p12.default.name=Basic Constraints Extension Default\npolicyset.set1.p12.default.params.basicConstraintsCritical=false\npolicyset.set1.p12.default.params.basicConstraintsIsCA=false\npolicyset.set1.p12.default.params.basicConstraintsPathLen=-1\npolicyset.set1.p13.constraint.class_id=noConstraintImpl\npolicyset.set1.p13.constraint.name=No Constraint\npolicyset.set1.p13.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.set1.p13.default.name=crlDistributionPointsExtDefaultImpl\npolicyset.set1.p13.default.params.crlDistPointsCritical=false\npolicyset.set1.p13.default.params.crlDistPointsNum=1\npolicyset.set1.p13.default.params.crlDistPointsEnable_0=false\npolicyset.set1.p13.default.params.crlDistPointsIssuerName_0=\npolicyset.set1.p13.default.params.crlDistPointsIssuerType_0=\npolicyset.set1.p13.default.params.crlDistPointsPointName_0=\npolicyset.set1.p13.default.params.crlDistPointsPointType_0=URIName\npolicyset.set1.p13.default.params.crlDistPointsReasons_0=\npolicyset.set1.p14.constraint.class_id=noConstraintImpl\npolicyset.set1.p14.constraint.name=No Constraint\npolicyset.set1.p14.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.set1.p14.default.name=AIA Extension Default\npolicyset.set1.p14.default.params.authInfoAccessADEnable_0=false\npolicyset.set1.p14.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.set1.p14.default.params.authInfoAccessADLocation_0=\npolicyset.set1.p14.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.set1.p14.default.params.authInfoAccessCritical=false\npolicyset.set1.p14.default.params.authInfoAccessNumADs=1\nprofileId=caTokenUserDelegateSigningKeyEnrollment\nclassId=caUserCertEnrollImpl\n' 2019-01-17T11:04:23Z DEBUG response status 409 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body '{"Attributes":{"Attribute":[]},"ClassName":"com.netscape.certsrv.base.ConflictingOperationException","Code":409,"Message":"Profile already exists"}' 2019-01-17T11:04:23Z DEBUG Error migrating 'caTokenUserDelegateSigningKeyEnrollment': Request failed with status 409: Non-2xx response from CA REST API: 409. Profile already exists 2019-01-17T11:04:23Z DEBUG request POST https://centos75.local:8443/ca/rest/profiles/caTokenUserDelegateSigningKeyEnrollment?action=enable 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 500 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 6208 Date: Thu, 17 Jan 2019 11:04:23 GMT Connection: close 2019-01-17T11:04:23Z DEBUG response body 'Apache Tomcat/7.0.76 - Error report

HTTP Status 500 - org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded


type Exception report

message org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded

description The server encountered an internal error that prevented it from fulfilling this request.

exception

org.jboss.resteasy.spi.UnhandledException: org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:157)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

root cause

org.jboss.resteasy.core.NoMessageBodyWriterFoundFailure: Could not find MessageBodyWriter for response object of type: com.netscape.certsrv.base.PKIException$Data of media type: application/x-www-form-urlencoded\n\torg.jboss.resteasy.core.ServerResponseWriter.writeNomapResponse(ServerResponseWriter.java:67)\n\torg.jboss.resteasy.core.SynchronousDispatcher.writeException(SynchronousDispatcher.java:153)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:372)\n\torg.jboss.resteasy.core.SynchronousDispatcher.invoke(SynchronousDispatcher.java:179)\n\torg.jboss.resteasy.plugins.server.servlet.ServletContainerDispatcher.service(ServletContainerDispatcher.java:220)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:56)\n\torg.jboss.resteasy.plugins.server.servlet.HttpServletDispatcher.service(HttpServletDispatcher.java:51)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:731)\n\tsun.reflect.GeneratedMethodAccessor41.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:175)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tsun.reflect.GeneratedMethodAccessor40.invoke(Unknown Source)\n\tsun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tjava.lang.reflect.Method.invoke(Method.java:498)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:288)\n\torg.apache.catalina.security.SecurityUtil$1.run(SecurityUtil.java:285)\n\tjava.security.AccessController.doPrivileged(Native Method)\n\tjavax.security.auth.Subject.doAsPrivileged(Subject.java:549)\n\torg.apache.catalina.security.SecurityUtil.execute(SecurityUtil.java:320)\n\torg.apache.catalina.security.SecurityUtil.doAsPrivilege(SecurityUtil.java:260)\n

note The full stack trace of the root cause is available in the Apache Tomcat/7.0.76 logs.


Apache Tomcat/7.0.76

' 2019-01-17T11:04:23Z DEBUG Failed to enable profile 'caTokenUserDelegateSigningKeyEnrollment' (it is probably already enabled) 2019-01-17T11:04:23Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:23Z DEBUG request body '' 2019-01-17T11:04:23Z DEBUG response status 204 2019-01-17T11:04:23Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=4CBCC90D612A8D004BE534CBEC2F9078; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:23 GMT 2019-01-17T11:04:23Z DEBUG response body '' 2019-01-17T11:04:23Z INFO [Ensuring presence of included profiles] 2019-01-17T11:04:23Z DEBUG Created connection context.ldap2_139822121620880 2019-01-17T11:04:23Z DEBUG Created connection context.ldap2_139822015374800 2019-01-17T11:04:23Z DEBUG flushing ldapi://%2fvar%2frun%2fslapd-LOCAL.socket from SchemaCache 2019-01-17T11:04:23Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-LOCAL.socket conn= 2019-01-17T11:04:24Z DEBUG Destroyed connection context.ldap2_139822015374800 2019-01-17T11:04:24Z DEBUG Created connection context.ldap2_139822015194320 2019-01-17T11:04:24Z DEBUG flushing ldapi://%2fvar%2frun%2fslapd-LOCAL.socket from SchemaCache 2019-01-17T11:04:24Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-LOCAL.socket conn= 2019-01-17T11:04:24Z DEBUG Destroyed connection context.ldap2_139822015194320 2019-01-17T11:04:24Z DEBUG flushing ldapi://%2fvar%2frun%2fslapd-LOCAL.socket from SchemaCache 2019-01-17T11:04:24Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-LOCAL.socket conn= 2019-01-17T11:04:24Z DEBUG Destroyed connection context.ldap2_139822121620880 2019-01-17T11:04:24Z INFO [Add default CA ACL] 2019-01-17T11:04:24Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:04:24Z DEBUG Created connection context.ldap2_139822040965520 2019-01-17T11:04:24Z DEBUG flushing ldapi://%2fvar%2frun%2fslapd-LOCAL.socket from SchemaCache 2019-01-17T11:04:24Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-LOCAL.socket conn= 2019-01-17T11:04:24Z DEBUG Destroyed connection context.ldap2_139822040965520 2019-01-17T11:04:24Z DEBUG Created connection context.ldap2_139822016833872 2019-01-17T11:04:24Z DEBUG flushing ldapi://%2fvar%2frun%2fslapd-LOCAL.socket from SchemaCache 2019-01-17T11:04:24Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-LOCAL.socket conn= 2019-01-17T11:04:24Z DEBUG Destroyed connection context.ldap2_139822016833872 2019-01-17T11:04:24Z DEBUG raw: caacl_find(None, version=u'2.229') 2019-01-17T11:04:24Z DEBUG caacl_find(None, all=False, raw=False, version=u'2.229', no_members=True, pkey_only=False) 2019-01-17T11:04:24Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:04:25Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:04:25Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:25Z DEBUG request body '' 2019-01-17T11:04:25Z DEBUG response status 200 2019-01-17T11:04:25Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=489FFCDD380580DE2A232DDBC457AD33; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:25 GMT 2019-01-17T11:04:25Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:25Z DEBUG request GET https://centos75.local:8443/ca/rest/profiles/caIPAserviceCert/raw 2019-01-17T11:04:25Z DEBUG request body '' 2019-01-17T11:04:25Z DEBUG response status 200 2019-01-17T11:04:25Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Content-Type: application/xml Content-Length: 7287 Date: Thu, 17 Jan 2019 11:04:25 GMT 2019-01-17T11:04:25Z DEBUG response body 'auth.instance_id=raCertAuth\nclassId=caEnrollImpl\ndesc=This certificate profile is for enrolling server certificates with IPA-RA agent authentication.\nenable=true\nenableBy=ipara\ninput.i1.class_id=certReqInputImpl\ninput.i2.class_id=submitterInfoInputImpl\ninput.list=i1,i2\nname=IPA-RA Agent-Authenticated Server Certificate Enrollment\noutput.list=o1\noutput.o1.class_id=certOutputImpl\npolicyset.list=serverCertSet\npolicyset.serverCertSet.1.constraint.class_id=subjectNameConstraintImpl\npolicyset.serverCertSet.1.constraint.name=Subject Name Constraint\npolicyset.serverCertSet.1.constraint.params.accept=true\npolicyset.serverCertSet.1.constraint.params.pattern=CN=[^,]+,.+\npolicyset.serverCertSet.1.default.class_id=subjectNameDefaultImpl\npolicyset.serverCertSet.1.default.name=Subject Name Default\npolicyset.serverCertSet.1.default.params.name=CN=$request.req_subject_name.cn$, O=LOCAL\npolicyset.serverCertSet.10.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.10.constraint.name=No Constraint\npolicyset.serverCertSet.10.default.class_id=subjectKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.10.default.name=Subject Key Identifier Extension Default\npolicyset.serverCertSet.10.default.params.critical=false\npolicyset.serverCertSet.11.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.11.constraint.name=No Constraint\npolicyset.serverCertSet.11.default.class_id=userExtensionDefaultImpl\npolicyset.serverCertSet.11.default.name=User Supplied Extension Default\npolicyset.serverCertSet.11.default.params.userExtOID=2.5.29.17\npolicyset.serverCertSet.12.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.12.constraint.name=No Constraint\npolicyset.serverCertSet.12.default.class_id=commonNameToSANDefaultImpl\npolicyset.serverCertSet.12.default.name=Copy Common Name to Subject Alternative Name\npolicyset.serverCertSet.2.constraint.class_id=validityConstraintImpl\npolicyset.serverCertSet.2.constraint.name=Validity Constraint\npolicyset.serverCertSet.2.constraint.params.notAfterCheck=false\npolicyset.serverCertSet.2.constraint.params.notBeforeCheck=false\npolicyset.serverCertSet.2.constraint.params.range=740\npolicyset.serverCertSet.2.default.class_id=validityDefaultImpl\npolicyset.serverCertSet.2.default.name=Validity Default\npolicyset.serverCertSet.2.default.params.range=731\npolicyset.serverCertSet.2.default.params.startTime=0\npolicyset.serverCertSet.3.constraint.class_id=keyConstraintImpl\npolicyset.serverCertSet.3.constraint.name=Key Constraint\npolicyset.serverCertSet.3.constraint.params.keyParameters=1024,2048,3072,4096,8192\npolicyset.serverCertSet.3.constraint.params.keyType=RSA\npolicyset.serverCertSet.3.default.class_id=userKeyDefaultImpl\npolicyset.serverCertSet.3.default.name=Key Default\npolicyset.serverCertSet.4.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.4.constraint.name=No Constraint\npolicyset.serverCertSet.4.default.class_id=authorityKeyIdentifierExtDefaultImpl\npolicyset.serverCertSet.4.default.name=Authority Key Identifier Default\npolicyset.serverCertSet.5.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.5.constraint.name=No Constraint\npolicyset.serverCertSet.5.default.class_id=authInfoAccessExtDefaultImpl\npolicyset.serverCertSet.5.default.name=AIA Extension Default\npolicyset.serverCertSet.5.default.params.authInfoAccessADEnable_0=true\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocationType_0=URIName\npolicyset.serverCertSet.5.default.params.authInfoAccessADLocation_0=http://ipa-ca.local/ca/ocsp\npolicyset.serverCertSet.5.default.params.authInfoAccessADMethod_0=1.3.6.1.5.5.7.48.1\npolicyset.serverCertSet.5.default.params.authInfoAccessCritical=false\npolicyset.serverCertSet.5.default.params.authInfoAccessNumADs=1\npolicyset.serverCertSet.6.constraint.class_id=keyUsageExtConstraintImpl\npolicyset.serverCertSet.6.constraint.name=Key Usage Extension Constraint\npolicyset.serverCertSet.6.constraint.params.keyUsageCritical=true\npolicyset.serverCertSet.6.constraint.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.constraint.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.constraint.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.constraint.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.6.default.class_id=keyUsageExtDefaultImpl\npolicyset.serverCertSet.6.default.name=Key Usage Default\npolicyset.serverCertSet.6.default.params.keyUsageCritical=true\npolicyset.serverCertSet.6.default.params.keyUsageCrlSign=false\npolicyset.serverCertSet.6.default.params.keyUsageDataEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageDecipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageDigitalSignature=true\npolicyset.serverCertSet.6.default.params.keyUsageEncipherOnly=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyAgreement=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyCertSign=false\npolicyset.serverCertSet.6.default.params.keyUsageKeyEncipherment=true\npolicyset.serverCertSet.6.default.params.keyUsageNonRepudiation=true\npolicyset.serverCertSet.7.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.7.constraint.name=No Constraint\npolicyset.serverCertSet.7.default.class_id=extendedKeyUsageExtDefaultImpl\npolicyset.serverCertSet.7.default.name=Extended Key Usage Extension Default\npolicyset.serverCertSet.7.default.params.exKeyUsageCritical=false\npolicyset.serverCertSet.7.default.params.exKeyUsageOIDs=1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2\npolicyset.serverCertSet.8.constraint.class_id=signingAlgConstraintImpl\npolicyset.serverCertSet.8.constraint.name=No Constraint\npolicyset.serverCertSet.8.constraint.params.signingAlgsAllowed=SHA1withRSA,SHA256withRSA,SHA512withRSA,MD5withRSA,MD2withRSA,SHA1withDSA,SHA1withEC,SHA256withEC,SHA384withEC,SHA512withEC\npolicyset.serverCertSet.8.default.class_id=signingAlgDefaultImpl\npolicyset.serverCertSet.8.default.name=Signing Alg\npolicyset.serverCertSet.8.default.params.signingAlg=-\npolicyset.serverCertSet.9.constraint.class_id=noConstraintImpl\npolicyset.serverCertSet.9.constraint.name=No Constraint\npolicyset.serverCertSet.9.default.class_id=crlDistributionPointsExtDefaultImpl\npolicyset.serverCertSet.9.default.name=CRL Distribution Points Extension Default\npolicyset.serverCertSet.9.default.params.crlDistPointsCritical=false\npolicyset.serverCertSet.9.default.params.crlDistPointsEnable_0=true\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerName_0=CN=Certificate Authority,o=ipaca\npolicyset.serverCertSet.9.default.params.crlDistPointsIssuerType_0=DirectoryName\npolicyset.serverCertSet.9.default.params.crlDistPointsNum=1\npolicyset.serverCertSet.9.default.params.crlDistPointsPointName_0=http://ipa-ca.local/ipa/crl/MasterCRL.bin\npolicyset.serverCertSet.9.default.params.crlDistPointsPointType_0=URIName\npolicyset.serverCertSet.9.default.params.crlDistPointsReasons_0=\npolicyset.serverCertSet.list=1,2,3,4,5,6,7,8,9,10,11,12\nprofileId=caIPAserviceCert\nvisible=false\n' 2019-01-17T11:04:25Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:25Z DEBUG request body '' 2019-01-17T11:04:25Z DEBUG response status 204 2019-01-17T11:04:25Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=40120DDB21C1AB8A5E26749B4D6A67B2; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:25 GMT 2019-01-17T11:04:25Z DEBUG response body '' 2019-01-17T11:04:25Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:04:25Z INFO [Set up lightweight CA key retrieval] 2019-01-17T11:04:25Z INFO Creating principal 2019-01-17T11:04:25Z DEBUG Starting external process 2019-01-17T11:04:25Z DEBUG args=kadmin.local -q addprinc -randkey dogtag/centos75.local@LOCAL -x ipa-setup-override-restrictions 2019-01-17T11:04:25Z DEBUG Process finished, return code=0 2019-01-17T11:04:25Z DEBUG stdout=Authenticating as principal root/admin@LOCAL with password. 2019-01-17T11:04:25Z DEBUG stderr=WARNING: no policy specified for dogtag/centos75.local@LOCAL; defaulting to no policy add_principal: Principal or policy already exists while creating "dogtag/centos75.local@LOCAL". 2019-01-17T11:04:25Z INFO Retrieving keytab 2019-01-17T11:04:25Z DEBUG Starting external process 2019-01-17T11:04:25Z DEBUG args=kadmin.local -q ktadd -k /etc/pki/pki-tomcat/dogtag.keytab dogtag/centos75.local@LOCAL -x ipa-setup-override-restrictions 2019-01-17T11:04:25Z DEBUG Process finished, return code=0 2019-01-17T11:04:25Z DEBUG stdout=Authenticating as principal root/admin@LOCAL with password. Entry for principal dogtag/centos75.local@LOCAL with kvno 3, encryption type aes256-cts-hmac-sha1-96 added to keytab WRFILE:/etc/pki/pki-tomcat/dogtag.keytab. Entry for principal dogtag/centos75.local@LOCAL with kvno 3, encryption type aes128-cts-hmac-sha1-96 added to keytab WRFILE:/etc/pki/pki-tomcat/dogtag.keytab. Entry for principal dogtag/centos75.local@LOCAL with kvno 3, encryption type des3-cbc-sha1 added to keytab WRFILE:/etc/pki/pki-tomcat/dogtag.keytab. Entry for principal dogtag/centos75.local@LOCAL with kvno 3, encryption type arcfour-hmac added to keytab WRFILE:/etc/pki/pki-tomcat/dogtag.keytab. Entry for principal dogtag/centos75.local@LOCAL with kvno 3, encryption type camellia128-cts-cmac added to keytab WRFILE:/etc/pki/pki-tomcat/dogtag.keytab. Entry for principal dogtag/centos75.local@LOCAL with kvno 3, encryption type camellia256-cts-cmac added to keytab WRFILE:/etc/pki/pki-tomcat/dogtag.keytab. 2019-01-17T11:04:25Z DEBUG stderr= 2019-01-17T11:04:25Z INFO Creating Custodia keys 2019-01-17T11:04:25Z DEBUG Created connection context.ldap2_139822041089808 2019-01-17T11:04:25Z DEBUG flushing ldapi://%2fvar%2frun%2fslapd-LOCAL.socket from SchemaCache 2019-01-17T11:04:25Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-LOCAL.socket conn= 2019-01-17T11:04:25Z DEBUG Destroyed connection context.ldap2_139822041089808 2019-01-17T11:04:25Z DEBUG Created connection context.ldap2_139822017122512 2019-01-17T11:04:25Z DEBUG flushing ldapi://%2fvar%2frun%2fslapd-LOCAL.socket from SchemaCache 2019-01-17T11:04:25Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-LOCAL.socket conn= 2019-01-17T11:04:26Z DEBUG Destroyed connection context.ldap2_139822017122512 2019-01-17T11:04:26Z INFO Configuring key retriever 2019-01-17T11:04:26Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:04:26Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2019-01-17T11:04:26Z DEBUG request GET https://centos75.local:8443/ca/rest/account/login 2019-01-17T11:04:26Z DEBUG request body '' 2019-01-17T11:04:26Z DEBUG response status 200 2019-01-17T11:04:26Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=944A463DEF249ECD01EB5A58D11AAA7D; Path=/ca; Secure; HttpOnly Content-Type: application/xml Content-Length: 218 Date: Thu, 17 Jan 2019 11:04:26 GMT 2019-01-17T11:04:26Z DEBUG response body 'iparaCertificate Manager AgentsRegistration Manager Agents' 2019-01-17T11:04:26Z DEBUG request GET https://centos75.local:8443/ca/rest/authorities/host-authority 2019-01-17T11:04:26Z DEBUG request body '' 2019-01-17T11:04:26Z DEBUG response status 200 2019-01-17T11:04:26Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Content-Type: application/json Transfer-Encoding: chunked Date: Thu, 17 Jan 2019 11:04:26 GMT 2019-01-17T11:04:26Z DEBUG response body '{"isHostAuthority":true,"id":"17d53c5d-6712-421f-9e72-f86430750a20","parentID":null,"issuerDN":"CN=Certificate Authority,O=LOCAL","serial":1,"dn":"CN=Certificate Authority,O=LOCAL","enabled":true,"description":"Host authority","ready":true,"link":null}' 2019-01-17T11:04:26Z DEBUG request GET https://centos75.local:8443/ca/rest/account/logout 2019-01-17T11:04:26Z DEBUG request body '' 2019-01-17T11:04:26Z DEBUG response status 204 2019-01-17T11:04:26Z DEBUG response headers Server: Apache-Coyote/1.1 Cache-Control: private Expires: Thu, 01 Jan 1970 01:00:00 CET Set-Cookie: JSESSIONID=6D810295761FEB1754B86ED0099417D2; Path=/ca; Secure; HttpOnly Content-Type: application/xml Date: Thu, 17 Jan 2019 11:04:26 GMT 2019-01-17T11:04:26Z DEBUG response body '' 2019-01-17T11:04:26Z DEBUG Created connection context.ldap2_139822017122704 2019-01-17T11:04:26Z DEBUG flushing ldapi://%2fvar%2frun%2fslapd-LOCAL.socket from SchemaCache 2019-01-17T11:04:26Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-LOCAL.socket conn= 2019-01-17T11:04:26Z DEBUG Destroyed connection context.ldap2_139822017122704 2019-01-17T11:04:26Z DEBUG Created connection context.ldap2_139822041288912 2019-01-17T11:04:26Z DEBUG flushing ldapi://%2fvar%2frun%2fslapd-LOCAL.socket from SchemaCache 2019-01-17T11:04:26Z DEBUG retrieving schema for SchemaCache url=ldapi://%2fvar%2frun%2fslapd-LOCAL.socket conn= 2019-01-17T11:04:26Z DEBUG Destroyed connection context.ldap2_139822041288912 2019-01-17T11:04:26Z ERROR IPA server upgrade failed: Inspect /var/log/ipaupgrade.log and run command ipa-server-upgrade manually. 2019-01-17T11:04:26Z DEBUG File "/usr/lib/python2.7/site-packages/ipapython/admintool.py", line 178, in execute return_value = self.run() File "/usr/lib/python2.7/site-packages/ipaserver/install/ipa_server_upgrade.py", line 54, in run server.upgrade() File "/usr/lib/python2.7/site-packages/ipaserver/install/server/upgrade.py", line 2085, in upgrade upgrade_configuration() File "/usr/lib/python2.7/site-packages/ipaserver/install/server/upgrade.py", line 1966, in upgrade_configuration set_sssd_domain_option('ipa_server_mode', 'True') File "/usr/lib/python2.7/site-packages/ipaserver/install/server/upgrade.py", line 1388, in set_sssd_domain_option sssdconfig.import_config() File "/usr/lib/python2.7/site-packages/SSSDConfig/__init__.py", line 1455, in import_config fd = open(configfile, 'r') 2019-01-17T11:04:26Z DEBUG The ipa-server-upgrade command failed, exception: IOError: [Errno 2] No such file or directory: '/etc/sssd/sssd.conf' 2019-01-17T11:04:26Z ERROR Unexpected error - see /var/log/ipaupgrade.log for details: IOError: [Errno 2] No such file or directory: '/etc/sssd/sssd.conf' 2019-01-17T11:04:26Z ERROR The ipa-server-upgrade command failed. See /var/log/ipaupgrade.log for more information